Signal

WordPress releases 7.0.4 to fix critical remote code execution vulnerability

Evidence first: scan the strongest sources, then decide whether to go deeper.

Published 2026-08-07 12:56 UTCUpdated 2026-08-13 12:53 UTC
rss
cveexploitssecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.
4 top sources shown
WordPress: CVSS (Max): None
AusCERT - Bulletins · News · portal.auscert.org.au · 2026-08-13 02:08 UTC
Vulnerability in Wordpress
NCSC-FI - Vulnerabilities · github.com · 2026-08-13 02:00 UTC
Vulnérabilité dans WordPress (13 août 2026)
CERT-FR (FR) - All · News · cert.ssi.gouv.fr · 2026-08-13 00:00 UTC
Overview

A severe remote code execution vulnerability (CVE-2026-65640) affecting WordPress installations using Imagick and Ghostscript has been patched in WordPress 7.0.4. The flaw allows attackers with Author-level or higher permissions to exploit malicious Postscript file uploads.

Entities
WordPress Foundation
Score total
1.34
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
  • The fix was just released on August 13, 2026, making immediate updates necessary.
  • The vulnerability affects a wide range of WordPress versions back to 4.7.
  • Multiple security agencies have issued advisories highlighting the severity.
Why it matters
  • The vulnerability allows remote code execution, risking site compromise and data breaches.
  • Attackers only need Author-level permissions, which are common on many WordPress sites.
  • Prompt patching is critical to prevent exploitation in the wild.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
  • WordPress 7.0.4 fixes a severe remote code execution vulnerability via malicious Postscript file uploads exploitable by Author-level users.
How sources frame it
  • WordPress Foundation: neutral
All evidence
All evidence
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
SecurityWeek · securityweek.com · 2026-08-13 12:53 UTC
WordPress: CVSS (Max): None
AusCERT - Bulletins · portal.auscert.org.au · 2026-08-13 02:08 UTC
Vulnerability in Wordpress
NCSC-FI - Vulnerabilities · github.com · 2026-08-13 02:00 UTC
Vulnérabilité dans WordPress (13 août 2026)
CERT-FR (FR) - All · cert.ssi.gouv.fr · 2026-08-13 00:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
  • SecurityWeek (1)
  • AusCERT - Bulletins (1)
  • NCSC-FI - Vulnerabilities (1)
  • CERT-FR (FR) - All (1)
Top origin domains (this list)
  • securityweek.com (1)
  • portal.auscert.org.au (1)
  • github.com (1)
  • cert.ssi.gouv.fr (1)