Arbitrary file upload in WordPress - CVE-2026-65640
Published: August 12, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unrestricted upload of file with dangerous type in the file upload functionality when processing a malicious Postscript file upload. A remote user with Author or higher privileges can upload a specially crafted Postscript file to execute arbitrary code.
Exploitation requires Imagick and Ghostscript to be in use on the server.
Affected software
Fedora
wordpress
How to mitigate CVE-2026-65640
wordpress - addressed in versions 6.9.7-1.el9, 6.9.7-1.el10_2, 6.9.7-1.fc43, 6.9.7-1.fc44, 7.0.4-1.el10_3