8.8

CVE-2026-65640

Medienbericht

Remote code execution vulnerability via malicious file upload by an Author level user or higher

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.

Prerequisites:
* Imagick and Ghostscript in use on the server
* A malicious user with the `upload_files` capability

This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Mögliche Gegenmaßnahme
WordPress Core: Install latest version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWordPress
Produkt WordPress
Default Statusunaffected
Version 0
Version < 7.0.4
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
System
Produkt WordPress Core
Version >= 7.0.0, < 7.0.4
Version >= 6.9.0, < 6.9.7
Version >= 6.8.0, < 6.8.8
Version >= 6.7.0, < 6.7.7
Version >= 6.6.0, < 6.6.7
Version >= 6.5.0, < 6.5.10
Version >= 6.4.0, < 6.4.10
Version >= 6.3.0, < 6.3.10
Version >= 6.2.0, < 6.2.11
Version >= 6.1.0, < 6.1.12
Version >= 6.0.0, < 6.0.14
Version >= 5.9.0, < 5.9.16
Version >= 5.8.0, < 5.8.15
Version >= 5.7.0, < 5.7.17
Version >= 5.6.0, < 5.6.19
Version >= 5.5.0, < 5.5.20
Version >= 5.4.0, < 5.4.21
Version >= 5.3.0, < 5.3.23
Version >= 5.2.0, < 5.2.26
Version >= 5.1.0, < 5.1.24
Version >= 5.0.0, < 5.0.27
Version >= 4.9.0, < 4.9.31
Version >= 4.8.0, < 4.8.30
Version >= 4.7.0, < 4.7.35
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.81% 0.54
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
HackerOne 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
VulnDex Intel
Media Report
20.08.2026 08:20
https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
Third Party Advisory