tech π‘οΈ WordPress RCE flaw patched in version 7.0.4
WordPress released version 7.0.4 to fix a critical Remote Code Execution vulnerability affecting sites using Imagick and Ghostscript. This flaw, tracked as CVE-2026-65640, allowed authenticated Author-level users to execute code via a malicious PNG file upload. The issue stemmed from ImageMagick trusting file extensions over actual content during media processing. The patch now scans uploaded files to block dangerous signatures like PostScript before object construction. Site owners must update immediately to secure their platforms against this risk.