8.8
CVE-2026-65640
- EPSS 0.81%
- Veröffentlicht 17.08.2026 20:55:33
- Zuletzt bearbeitet 18.08.2026 16:18:12
- CVE-Watchlists
- Unerledigt
Remote code execution vulnerability via malicious file upload by an Author level user or higher
WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
Mögliche Gegenmaßnahme
WordPress Core: Install latest version
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWordPress
≫
Produkt
WordPress
Default Statusunaffected
Version
0
Version <
7.0.4
Status
affected
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
System
≫
Produkt
WordPress Core
Version
>= 7.0.0, < 7.0.4
Version
>= 6.9.0, < 6.9.7
Version
>= 6.8.0, < 6.8.8
Version
>= 6.7.0, < 6.7.7
Version
>= 6.6.0, < 6.6.7
Version
>= 6.5.0, < 6.5.10
Version
>= 6.4.0, < 6.4.10
Version
>= 6.3.0, < 6.3.10
Version
>= 6.2.0, < 6.2.11
Version
>= 6.1.0, < 6.1.12
Version
>= 6.0.0, < 6.0.14
Version
>= 5.9.0, < 5.9.16
Version
>= 5.8.0, < 5.8.15
Version
>= 5.7.0, < 5.7.17
Version
>= 5.6.0, < 5.6.19
Version
>= 5.5.0, < 5.5.20
Version
>= 5.4.0, < 5.4.21
Version
>= 5.3.0, < 5.3.23
Version
>= 5.2.0, < 5.2.26
Version
>= 5.1.0, < 5.1.24
Version
>= 5.0.0, < 5.0.27
Version
>= 4.9.0, < 4.9.31
Version
>= 4.8.0, < 4.8.30
Version
>= 4.7.0, < 4.7.35
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.81% | 0.54 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| HackerOne | 8.8 | 2.8 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-434 Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w