Rıdvan Yağlı[verified]@ridvanyagliDisclosure
WordPress CVE-2026-65640 allows remote code execution for Author‑privileged users via a specially crafted PNG processed by Imagick with Ghostscript; the vulnerability was patched in WordPress 7.0.4.
connect24h[verified]@connect24hPatch
The CVE-2026-65640 enables RCE via image upload for users with Author privileges using Imagick and Ghostscript, and the text emphasizes the importance of applying the 7.0.4 patch to mitigate the risk.
Netlas.io[verified]@Netlas_ioDisclosure
A newly disclosed WordPress CVE‑2026‑65640 enables Authenticated Remote Code Execution by allowing users with Author-level privileges to upload malicious Postscript files, impacting sites that use Imagick and Ghostscript.
ThreatWire[verified]@ThreatWire_Patch
WordPress highlighted a critical Author-level RCE (CVE‑2026‑65640) caused by image uploads using Imagick + Ghostscript, and urged immediate patching to version 7.0.4 or later.
The CyberSec Guru[verified]@thecybersecguruPatch
The post announces that WordPress 7.0.4 addresses CVE‑2026‑65640, detailing how the authenticated remote‑code‑execution flaw works through an image upload chain and outlining the applied fix.
MagicWP[verified]@magicwp_ioPatch
The post announces that WordPress 7.0.4 includes a patch for CVE-2026-65640, an author‑level RCE limited to servers with Imagick and Ghostscript, and advises users to check exposure and apply the update.
Cloudflare Changelog[verified]@CFchangelogPatch
Cloudflare’s WAF update on 2026‑08‑17 adds rule metadata for CVE‑2026‑65640, maintaining existing blocking behavior without altering detection.
Nitin Gavhane[verified]@NitinGavhane_Patch
The tweet announces that WordPress has released an emergency update that patches CVE‑2026‑65640, a low‑privilege RCE chain exploiting ImageMagick, and notes the fix is available.