Vulnerability identifier: #VU141728
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-65640
CWE-ID: CWE-434
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unrestricted upload of file with dangerous type in the file upload functionality when processing a malicious Postscript file upload. A remote user with Author or higher privileges can upload a specially crafted Postscript file to execute arbitrary code.
Exploitation requires Imagick and Ghostscript to be in use on the server.
Affected software
WordPress
How to mitigate CVE-2026-65640
Install security update from vendor's website.
WordPress - addressed in versions 4.7.35, 4.8.30, 4.9.31, 5.0.27, 5.1.24, 5.2.26, 5.3.23, 5.4.21, 5.5.20, 5.6.19, 5.7.17, 5.8.15, 5.9.16, 6.0.14, 6.1.12, 6.2.11, 6.3.10, 6.4.10, 6.5.10, 6.6.7, 6.7.7, 6.8.8, 6.9.7, 7.0.4
External References
Related Security Bulletins