CVE-2026-65640
Received Received - Intake

Remote Code Execution in WordPress via Malicious Postscript File Upload

Vulnerability report for CVE-2026-65640, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-17

Last updated on: 2026-08-17

Assigner: HackerOne

Description

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-17
Last Modified
2026-08-17
Generated
2026-08-18
AI Q&A
2026-08-18
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wordpress wordpress From 4.7 (exc)
wordpress wordpress to 7.0.4 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows an attacker with Author-level access or higher to upload a malicious Postscript file, which can lead to remote code execution on the server. It requires the server to have Imagick and Ghostscript installed.

Impact Analysis

An attacker could execute arbitrary code on your server, potentially taking control of your website, stealing data, or installing malware. This could disrupt services and compromise sensitive information.

Compliance Impact

This vulnerability could lead to data breaches, violating GDPR and HIPAA requirements for data protection and security. Non-compliance may result in legal penalties and reputational damage.

Mitigation Strategies

Update WordPress to version 7.0.4 or apply the backported fix to versions 4.7 and above. Remove upload_files capability from Author level users or higher if not required. Disable Imagick and Ghostscript if not essential to operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-65640. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart