CVE-2026-65640Patch

MEDIUMCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 19 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 40 mentions across 8 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 34 signals
  • Technical details provided in 38 signals
  • Disclosure: 6 classified signals
  • General: 3 classified signals
  • Peaked 6d ago at 19 mentions (2026-08-13); latest day: 1
  • 40 total mentions across 8 days

Deep dive

Activity timeline40 mentions / 8d
05101419Mentions · 2026-08-12: 4Mentions · 2026-08-13: 19Mentions · 2026-08-14: 7Mentions · 2026-08-16: 1Mentions · 2026-08-17: 3Mentions · 2026-08-20: 4Mentions · 2026-08-27: 1Mentions · 2026-09-04: 1PoC Mentioned / Linked · 2026-08-12: 1PoC Mentioned / Linked · 2026-08-13: 2Active Exploitation · 2026-08-12: 1Active Exploitation · 2026-08-13: 1Patch / Workaround · 2026-08-12: 4Patch / Workaround · 2026-08-13: 16Patch / Workaround · 2026-08-14: 5Patch / Workaround · 2026-08-16: 1Patch / Workaround · 2026-08-17: 3Patch / Workaround · 2026-08-20: 3Patch / Workaround · 2026-08-27: 1Patch / Workaround · 2026-09-04: 1Technical Details · 2026-08-12: 4Technical Details · 2026-08-13: 18Technical Details · 2026-08-14: 7Technical Details · 2026-08-16: 1Technical Details · 2026-08-17: 3Technical Details · 2026-08-20: 3Technical Details · 2026-08-27: 1Technical Details · 2026-09-04: 108-1208-1308-1408-1608-1708-2008-2709-04
Signal classification4 categories
Patch
3075.0%
Disclosure
615.0%
General
37.5%
Active Exploitation
12.5%
Referenced assets27 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-124
Patch4
2026-08-1319
Active Exploitation1Disclosure2General2Patch14
2026-08-147
Disclosure2Patch5
2026-08-161
Patch1
2026-08-173
General1Patch2
2026-08-204
Disclosure2Patch2
2026-08-271
Patch1
2026-09-041
Patch1
Full discourse20 posts
  • pwn.ai@pwn_ai
    Patch

    WordPress just released another emergency update (after XSS2Shell) patching another RCE chain reported by @pwn_ai: CVE-2026-65640 https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ This one lets anyone with the lowest privilege (Author) execute system commands. This is based on our previous ImageMagick research. This is under a week after our preauth XSS chain was patched. Kudos to the team. More on this soon

    Post summary

    WordPress issues an emergency patch for CVE-2026-65640, which permits low‑privilege authors to run system commands. The post highlights the vulnerability details and the rapid vendor response.

    321187309.3K
    12.0K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 WordPress için kritik CVE-2026-65640 RCE açığı! Eğer bir WordPress sitesinde Imagick (ImageMagick PHP uzantısı) etkinse ve sunucuda Ghostscript kuruluysa, Author (Yazar) yetkisine sahip bir kullanıcı PNG gibi görünen özel hazırlanmış bir dosya yükleyerek sunucuda uzaktan kod çalıştırabilir (RCE). Not: Açığın sömürülebilmesi için saldırganın en az Author (Yazar) yetkisine sahip olması gerekiyor. Yani bu, tamamen dışarıdan ve giriş yapmadan gerçekleştirilebilen bir saldırı değil. Açık WordPress 7.0.4 sürümünde kapatıldı. Özellikle çok yazarlı, üyelik sistemi bulunan veya yükleme yetkisi verilen WordPress sitelerinin en kısa sürede güncellenmesi öneriliyor. https://wordpress.org/news/2026/08/wordpress-7-0-4-release/

    Post summary

    WordPress CVE-2026-65640 allows remote code execution for Author‑privileged users via a specially crafted PNG processed by Imagick with Ghostscript; the vulnerability was patched in WordPress 7.0.4.

    01031184.0K
    2.4K followersView on X
  • connect24h@connect24h
    Patch

    祭り再び。WordPress使っている会社、7.0.4は早めに確認した方がいい。 今回修正されたのは 「画像アップロード → サーバ上でコード実行」につながるRCE。 CVE-2026-65640 条件は、 ・Author権限以上のユーザー ・Imagickを利用 ・Ghostscriptを利用 という構成。 つまり「誰でも外部から即RCE」という話ではない。 ただし、投稿者・編集者アカウントが奪われた後の侵害拡大ルートとしてはかなり嫌な脆弱性である。 しかもWordPressは8月6日に7.0.3を出したばかりで、8月12日に7.0.4。 最近のWordPressを見ると、 「自動更新できないから止めています」 という運用そのものが、かなり大きなリスクになってきた。 自社で迅速に更新できないWordPressは、 マネージド環境への移行まで含めて考える時期だと思う。 https://wordpress.org/news/2026/08/wordpress-7-0-4-releas #WordPress #脆弱性 #サイバーセキュリティ #CSIRT

    Post summary

    The CVE-2026-65640 enables RCE via image upload for users with Author privileges using Imagick and Ghostscript, and the text emphasizes the importance of applying the 7.0.4 patch to mitigate the risk.

    015121107.4K
    7.6K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-65640: Authenticated RCE in WordPress, 8.8 rating 🔥 A recently disclosed vulnerability in WordPress allows an attacker with an Author-level privileges to upload malicious Postscript files, which could lead to RCE. This issue affects sites that use Imagick and Ghostscript. 👉 https://nt.ls/LrDYt

    Post summary

    A newly disclosed WordPress CVE‑2026‑65640 enables Authenticated Remote Code Execution by allowing users with Author-level privileges to upload malicious Postscript files, impacting sites that use Imagick and Ghostscript.

    0402281.3K
    7.7K followersView on X
  • ThreatWire@ThreatWire_
    Patch

    🚨 CRITICAL: WordPress 7.0.4 patches CVE-2026-65640, an Author-level RCE affecting sites using Imagick + Ghostscript. A malicious file upload can lead to remote code execution on the server, turning a compromised Author account into a potential server takeover. The flaw affects WordPress branches back to 4.7. WordPress urges users to update immediately. #WordPress #CVE #RCE #CyberSecurity #WebSecurity #Infosec

    Post summary

    WordPress highlighted a critical Author-level RCE (CVE‑2026‑65640) caused by image uploads using Imagick + Ghostscript, and urged immediate patching to version 7.0.4 or later.

    1501973.1K
    1.6K followersView on X
  • The CyberSec Guru@thecybersecguru
    Patch

    🚨 WordPress 7.0.4 fixes CVE-2026-65640, an authenticated RCE that turns a malicious image upload into potential server-side code execution. I broke down the technical attack chain, validation bypass, Imagick/ImageMagick behavior, Ghostscript boundary, exploitation requirements, and the 7.0.4 fix: https://thecybersecguru.com/news/wordpress-7-0-4-cve-2026-65640-imagick-rce/ The interesting part? An Author-level account could abuse a crafted file that looks like a PNG but is actually interpreted as PostScript. The attack chain crosses: WordPress → Imagick → ImageMagick → Ghostscript → RCE The flaw also exposed alternate upload paths that could bypass WordPress's normal file-content validation.

    Post summary

    The post announces that WordPress 7.0.4 addresses CVE‑2026‑65640, detailing how the authenticated remote‑code‑execution flaw works through an image upload chain and outlining the applied fix.

    21011337.4K
    1.6K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    WordPress 7.0.4 patches CVE-2026-65640, an Author-level remote code execution bug on sites using Imagick and Ghostscript. Update now. #WordPress #CVE202665640 #RCE #Imagick #Ghostscript #WebSecurity #Cybersecurity https://securityonline.info/wordpress-7-0-4-rce-cve-2026-65640/

    Post summary

    WordPress 7.0.4 has patched CVE‑2026‑65640, an author‑level remote code execution flaw involving Imagick and Ghostscript, and users are advised to update immediately.

    031100710
    13.0K followersView on X
  • Mohammad Ebrahim Aali@moh_e_a
    Patch

    #وردپرس ها رو آپدیت کنید به نسخه 7.0.4 که ظاهرا اوضاع خیطه! آسیب پذیری پچ شده در هسته وردپرس از نوع RCE با امتیاز 8.8 (CVE-2026-65640) هکر با حداقل دسترسی میتونسته با آپلود یک فایل مخرب به جای تصویر، کنترل سرور رو به دست بگیره! قبل از آپدیت، بکاپ از دیتابیس و فایل ها فراموش نشه. https://t.co/pcZDlMkASN

    Post summary

    WordPress core has a patched RCE vulnerability (CVE-2026-65640) with a high CVSS score; attackers can exploit it via malicious file upload. Users are advised to update to version 7.0.4 and backup before applying the update.

    0101301.2K
    1.2K followersView on X
  • MagicWP@magicwp_io
    Patch

    WordPress 7.0.4 patches CVE-2026-65640, an Author-level RCE that only bites if your server runs Imagick + Ghostscript. We broke down how to check your exposure and update safely on the blog. https://magicwp.io/blog/wordpress-7-0-4-cve-2026-65640 #WordPressSecurity #CVE

    Post summary

    The post announces that WordPress 7.0.4 includes a patch for CVE-2026-65640, an author‑level RCE limited to servers with Imagick and Ghostscript, and advises users to check exposure and apply the update.

    02191519
    15 followersView on X
  • Cloudflare Changelog@CFchangelog
    Patch

    WAF Release 2026-08-17 updated WordPress RCE rule metadata to identify CVE-2026-65640. The rule continues to block attacks with no change to detection behavior. https://developers.cloudflare.com/changelog/post/2026-08-17-waf-release/

    Post summary

    Cloudflare’s WAF update on 2026‑08‑17 adds rule metadata for CVE‑2026‑65640, maintaining existing blocking behavior without altering detection.

    020441.5K
    5.2K followersView on X
  • Nitin Gavhane@NitinGavhane_
    Patch

    WordPress just shipped another emergency security update, patching CVE-2026-65640—an RCE chain reported by @pwn_ai. https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ The bug reportedly allows a low-privileged Author account to execute system commands, building on previous ImageMagick research. This comes less than a week after the pre-auth XSS chain was patched. Kudos to the WordPress team. More details soon. #WordPress #CyberSecurity #RCE #CVE #AppSec #InfoSec

    Post summary

    The tweet announces that WordPress has released an emergency update that patches CVE‑2026‑65640, a low‑privilege RCE chain exploiting ImageMagick, and notes the fix is available.

    02071317
    3.3K followersView on X
  • OS社長 | HP×LLMO@neo_vision11
    Active Exploitation

    WordPress、この6日間でセキュリティリリースが2回出ています。 【8/6】CVE-2026-64638(CVSS 8.9) ログイン画面の不具合を悪用するものです。ログイン中の管理者を攻撃者のページへ誘導してクリックさせることで、サーバー上でPHPを実行されるところまで実証されています。 すでに実際の攻撃も観測されています。 【8/12】CVE-2026-65640 画像処理にImagick+Ghostscriptを使っている環境で、投稿者以上の権限があればファイルアップロード経由でリモートコード実行が可能です。 修正は4.7ブランチまで戻されています。 今すぐやること ・管理画面の「更新」を開き、最新版になっているか目で確認 ・自動更新を入れていても、失敗して止まっているケースがあるので要確認 ・管理者・編集者権限を誰が持っているか棚卸し お盆で制作会社と連絡がつかない、そもそも見方が分からない、という方はリプかDMで声をかけてください。 確認だけでもお手伝いします。

    Post summary

    The text reports two WordPress CVEs, emphasizing that CVE-2026-64638 is actively exploited in the wild with demonstrated PHP code execution, while CVE-2026-65640 has a backported fix; it urges immediate update verification and privilege audits.

    00070141
    1.8K followersView on X
  • BugShield@BugShieldWP
    Patch

    WordPress 7.0.4 is out. CVE-2026-65640 is an Author-level Postscript upload that can become RCE if Imagick + Ghostscript are on the server. Update today. Then check who can still upload media. https://bugshield.co.uk/blog/wordpress-7-0-4-postscript-rce

    Post summary

    WordPress 7.0.4 was released to patch CVE‑2026‑65640, an author‑level Postscript upload vulnerability that could lead to RCE when Imagick and Ghostscript are present; users are urged to update immediately.

    01050122
    21 followersView on X
  • Aikido Community Japan@AikidoCommJP
    General

    6日前に直ったWordPress「本体」のRCEが、8/17分のaikido intel パッケージ監視で「新着」として出てくる。 脆弱性の「日付」の話として、これが地味に面白い。 CVE-2026-65640。CVSS 8.8。 WordPressは8/12に7.0.4で修正済み。 Author以上の権限+Imagick/Ghostscriptを使う環境で、細工したPostScriptファイルを踏ませるとRCEにつながる。 仕組みは、ImageTragickを思わせるもの。 WordPress側は拡張子などを見て画像として扱う一方、Imagickは実際の中身を見て形式を判断する。 「画像に見えるファイル」の中身がPostScriptなら、Ghostscriptまで処理が渡ってしまう。 そして8/17分のAikido Intelでは、このCVEが johnpbloch/wordpress-core roots/wordpress というWordPress本体のComposerミラーに対する脆弱性として新着に出てきた。 同じCVEでも、 ベンダーが修正した日 GitHub Advisoryが公開された日 各パッケージ監視に現れる日 は、必ずしも同じではない。 ここが脆弱性監視の難しいところだと思う。 一つのFeedだけ見ていると、 「8/12に終わった話」 が、別の監視面では 「8/17に新しく来た脆弱性」 になる。 しかも「修正済み=もう見る必要がない」でもない。 XML-RPCのwp.uploadFileやMP3のカバーアート抽出など、通常のアップロード検査とは別の経路から到達できる点も指摘されている。 XML-RPCは標準で有効。 KEV未掲載=安全でもない。 脆弱性には一つの「公開日」があるのではなく、観測する場所ごとに違う時間軸がある。 だから監視の入口も、一つでは足りない。 https://rocket-boys.co.jp/security-measures-lab/wordpress-security-update-vulnerability-cve-2026-65640/ #WordPress #脆弱性 #脆弱性管理 #AppSec #AikidoIntel

    Post summary

    The post reports that WordPress patched CVE‑2026‑65640 on 12 Aug, yet monitoring feeds still list it as new on 17 Aug, highlighting inconsistencies in vulnerability tracking.

    00031551
    860 followersView on X
  • Sam Stepanyan@securestep9
    Patch

    #WordPress: Yet another AI-discovered(@pwn_ai) Critical WordPress #RCE #Vulnerability CVE-2026-65640 Allows Authors to Execute Code via Malicious PNG File (via Imagemagick). Patched WordPress version 7.0.4 is now available, older versions backported: 👇 https://cybersecuritynews.com/wordpress-imagick-rce-vulnerability

    Post summary

    The post announces CVE‑2026‑65640, a WordPress RCE via malicious PNG using Imagemagick, and provides a patch (v7.0.4) and backport details.

    00040324
    7.4K followersView on X
  • Mister WordPress Ⓦ 🌶️@MisterWordPress
    Patch

    💀 Faille WordPress (CVE-2026-65640). RCE authentifié (si compte avec rôle Auteur+) via upload de fichier malveillant, uniquement si Imagick + Ghostscript sont présents sur le serveur (fréquent). Patchée en 7.0.4 → updatez vos sites pour être safes ! Source : ↓ https://t.co/sYb1HppE5c

    Post summary

    CVE‑2026‑65640 is an authenticated remote code execution flaw in WordPress that requires an Author+ account and the presence of Imagick and Ghostscript. It has been patched in version 7.0.4; sites should update to mitigate the risk.

    20010211
    3.4K followersView on X
  • lee1981@lee1981b
    Patch

    🔥 CyberForge CVE of the Day #023 🚨 CVE-2026-65640 — WordPress has patched a High-severity authenticated RCE that could allow an Author-level user or anyone with `upload_files` to execute code on the server. 🔑Key details ⭐ Severity: High — CVSS 8.8 ⭐ Important correction: the published score is CVSS v3.0, not v4.0 ⭐ CWE: CWE-434 — Dangerous File Upload ⭐ Affected: WordPress 4.7.0 through 7.0.3 ⭐ Primary fix: WordPress 7.0.4 ⭐ Older branches: fixes backported through 4.7.35 ⭐ User interaction: None Required conditions ✅ Attacker has an upload-capable account ✅ WordPress uses Imagick/ImageMagick ✅ Ghostscript is available to process the content How it works: WordPress could trust an innocent-looking image filename while Imagick inspected the actual contents. A disguised PostScript-family file could consequently reach Ghostscript and trigger server-side code execution. The patch hardens `WP_Image_Editor_Imagick::load()` by checking real file headers, dangerous format prefixes, PostScript/EPS signatures, fake PDFs and compressed wrappers before Imagick processes them. 🚨 Current exploitation status — 13 August 2026 • CISA KEV: Not listed • EPSS: No score yet • Public PoC: None verified • Active exploitation: None verified ⚠️ These findings are time-sensitive. The public patch gives attackers enough information to begin reverse-engineering the flaw. 🛡️ Defensive action: 1. Update to 7.0.4 or the patched release for your branch. 2. Audit all users and custom roles with `upload_files`. 3. Remove stale Author accounts and enforce MFA. 4. Disable XML-RPC if unused—but do not treat that as a patch replacement. 5. Hunt for suspicious uploads, unexpected PHP files, new administrators and unusual PHP → ImageMagick → Ghostscript process chains. 🔥 CyberForge Verdict: Patch now, especially on multi-author, membership, publishing, educational and agency-managed sites. An ordinary editorial permission becoming server-level code execution is a serious trust-boundary failure. 🔗 WordPress advisory: https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w 🔗 Release information: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ #CyberForge #CVE #WordPress #RCE #CyberSecurity #BlueTeam

    Post summary

    The post outlines a high‑severity authenticated RCE in WordPress, details the vulnerability extensively, and emphasizes applying the available patch and defensive measures, with no evidence of active exploitation or PoC availability.

    00020119
    556 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    【重要】WordPressにCVSS 8.8のRCE、7.0.4へ更新を https://www.cybernote.click/2026/08/27/wordpress-cve-2026-65640-author-rce-update/ #IT #Security #cybersecurity

    Post summary

    The post warns of a CVSS 8.8 remote code execution vulnerability (CVE‑2026‑65640) in WordPress and advises updating to version 7.0.4.

    0001063
    206 followersView on X
  • Tech Start XYZ@TechStartXYZ
    Patch

    O alerta coincide com o lançamento do WordPress 7.0.4, que fechou outra falha crítica (CVE-2026-65640, CVSS 8.8) envolvendo execução remota de código via arquivos PostScript no processamento do ImageMagick/Ghostscript. O ecossistema WordPress está sob varredura pesada de bots em busca de brechas em formulários e uploads de mídia.

    Post summary

    WordPress 7.0.4 releases patch for CVE-2026-65640, a high‑severity RCE flaw in ImageMagick/Ghostscript; no PoC, exploit code, or active exploitation reported.

    1000040
    168 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Patch

    WordPress、投稿者権限以上でRCEにつながる脆弱性を修正-CVE-2026-65640 https://rocket-boys.co.jp/security-measures-lab/wordpress-security-update-vulnerability-cve-2026-65640/ #セキュリティ対策Lab #security #securitynews #脆弱性

    Post summary

    The article announces a patch for CVE-2026-65640, a WordPress RCE vulnerability affecting author-level accounts, and directs readers to a link for more details.

    00001156
    548 followersView on X

Explore more