Arbitrary file upload in WordPress - CVE-2026-65640

 

Arbitrary file upload in WordPress - CVE-2026-65640

Published: August 12, 2026


Vulnerability identifier: #VU141728
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-65640
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to unrestricted upload of file with dangerous type in the file upload functionality when processing a malicious Postscript file upload. A remote user with Author or higher privileges can upload a specially crafted Postscript file to execute arbitrary code.

Exploitation requires Imagick and Ghostscript to be in use on the server.


Affected software

WordPress

How to mitigate CVE-2026-65640

Install security update from vendor's website.

WordPress - addressed in versions 4.7.35, 4.8.30, 4.9.31, 5.0.27, 5.1.24, 5.2.26, 5.3.23, 5.4.21, 5.5.20, 5.6.19, 5.7.17, 5.8.15, 5.9.16, 6.0.14, 6.1.12, 6.2.11, 6.3.10, 6.4.10, 6.5.10, 6.6.7, 6.7.7, 6.8.8, 6.9.7, 7.0.4

External References

Related Security Bulletins