Close Menu

    Subscribe to Updates

    Get the latest Tech news from SynapseFlow

    What's Hot

    Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    August 14, 2026

    APOD: 2026 August 14 – Total Solar Eclipse from Greenland

    August 14, 2026

    This HP laptop deal gets you Windows 11 and Microsoft 365 for $300

    August 14, 2026
    Facebook X (Twitter) Instagram
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube
    synapseflow.co.uksynapseflow.co.uk
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    synapseflow.co.uksynapseflow.co.uk
    Home»Cybersecurity»WordPress 7.0.4 Patches Remote Code Execution Vulnerability
    WordPress 7.0.4 Patches Remote Code Execution Vulnerability
    Cybersecurity

    WordPress 7.0.4 Patches Remote Code Execution Vulnerability

    The Tech GuyBy The Tech GuyAugust 14, 2026No Comments2 Mins Read0 Views
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Advertisement


    WordPress on Wednesday announced patches for a high-severity vulnerability that allows authenticated attackers to execute arbitrary code remotely.

    Advertisement

    Tracked as CVE-2026-65640 (CVSS score of 8.8), the security defect can be exploited by attackers with Author-level user or higher permissions via malicious Postscript file uploads.

    According to WordPress’ advisory, the issue affects only installations that use Imagick and Ghostscript, as it was discovered in Ghostscript’s handling of certain embedded files. Successful exploitation requires that an attacker has file upload rights.

    “WordPress version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches, the fix has been backported to all branches back to 4.7,” the web content management system’s maintainers announced.

    The vulnerability resides in how ImageMagick (through the Imagick extension) and WordPress handle various types of files: ImageMagick looks at the contents, while WordPress looks at the file extension, vulnerability management firm Patchstack explains.

    While WordPress passes an uploaded file to ImageMagick based on its extension, ImageMagick looks at the content and, if it detects PostScript inside, calls Ghostscript to render it.

    Advertisement. Scroll to continue reading.

    This allows an attacker to upload a PNG file containing PostScript, which will be executed in Ghostscript as a PostScript program. While WordPress does contain a function that performs content checks, some upload methods do not, opening the door for exploitation, Patchstack says.

    WordPress addressed the security defect by modifying the load() function to check the file’s contents before passing it to Imagick, preventing PostScript execution. The fix also prevents attackers from using filenames to manipulate Imagick into using Ghostscript.

    “If you run a multi-author publication, a membership site, a client site with contributors, or anything with open or loosely managed registration, […] an Author uploading a booby-trapped ‘image’ is a genuinely realistic threat, not a theoretical one,” Patchstack notes.

    Related: Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    Related: Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack

    Related: Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    Related: SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

    Advertisement
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    The Tech Guy
    • Website

    Related Posts

    Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    August 14, 2026

    In Other News: Rapid7 Layoffs, Hacking a Boeing 737, Refrigeration System Vulnerabilities

    August 14, 2026

    Adobe Commerce Bug Targeted Immediately After Disclosure

    August 13, 2026

    Cybersecurity M&A Roundup: 21 Deals Announced in July 2026

    August 13, 2026

    Venture Firm Team8 Secures Additional $365 Million

    August 13, 2026

    Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset

    August 13, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    You don’t need a NAS to self-host — I proved it with hardware from my closet

    June 7, 2026391 Views

    Spotify is giving one of its best playlists a big visual upgrade to give subscribers ‘a closer connection’ to its New Music Friday curators — and I think it could be the update it’s always needed

    June 12, 2026210 Views

    The iPad Air brand makes no sense – it needs a rethink

    October 12, 202516 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Advertisement
    About Us
    About Us

    SynapseFlow brings you the latest updates in Technology, AI, and Gadgets from innovations and reviews to future trends. Stay smart, stay updated with the tech world every day!

    Our Picks

    Trivy, Not LiteLLM Behind the 2,500 Org Compromise

    August 14, 2026

    APOD: 2026 August 14 – Total Solar Eclipse from Greenland

    August 14, 2026

    This HP laptop deal gets you Windows 11 and Microsoft 365 for $300

    August 14, 2026
    categories
    • AI News & Updates
    • Cybersecurity
    • Future Tech
    • Reviews
    • Software & Apps
    • Tech Gadgets
    Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
    • Homepage
    • About Us
    • Contact Us
    • Privacy Policy
    © 2026 SynapseFlow All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.