Signal
WordPress releases 7.0.4 to fix critical remote code execution vulnerability
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-08-07 12:56 UTCUpdated 2026-08-13 12:53 UTC
rss
cveexploitssecurity_toolingincident_response
Trend in the last 24h
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (4 domains)domains are deduped. counts indicate coverage, not truth.4 top sources shown
Overview
A severe remote code execution vulnerability (CVE-2026-65640) affecting WordPress installations using Imagick and Ghostscript has been patched in WordPress 7.0.4. The flaw allows attackers with Author-level or higher permissions to exploit malicious Postscript file uploads.
Entities
WordPress Foundation
Score total
1.34
Momentum 24h
4
Posts
4
Origins
4
Source types
1
Duplicate ratio
0%
Why now
- The fix was just released on August 13, 2026, making immediate updates necessary.
- The vulnerability affects a wide range of WordPress versions back to 4.7.
- Multiple security agencies have issued advisories highlighting the severity.
Why it matters
- The vulnerability allows remote code execution, risking site compromise and data breaches.
- Attackers only need Author-level permissions, which are common on many WordPress sites.
- Prompt patching is critical to prevent exploitation in the wild.
LLM analysis
Topic mix: lowPromo risk: lowSource quality: medium
Recurring claims
- WordPress 7.0.4 fixes a severe remote code execution vulnerability via malicious Postscript file uploads exploitable by Author-level users.
How sources frame it
- WordPress Foundation: neutral
All evidence
All evidence
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
SecurityWeek · securityweek.com · 2026-08-13 12:53 UTC
WordPress: CVSS (Max): None
AusCERT - Bulletins · portal.auscert.org.au · 2026-08-13 02:08 UTC
Vulnerability in Wordpress
NCSC-FI - Vulnerabilities · github.com · 2026-08-13 02:00 UTC
Vulnérabilité dans WordPress (13 août 2026)
CERT-FR (FR) - All · cert.ssi.gouv.fr · 2026-08-13 00:00 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 4Origin domains: 4Duplicates: -
Showing 4 / 0
Top publishers (this list)
- SecurityWeek (1)
- AusCERT - Bulletins (1)
- NCSC-FI - Vulnerabilities (1)
- CERT-FR (FR) - All (1)
Top origin domains (this list)
- securityweek.com (1)
- portal.auscert.org.au (1)
- github.com (1)
- cert.ssi.gouv.fr (1)