Vulnerabilities & PatchesEmerging1 src
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
WordPress has released version 7. 0. 4, a security-focused update that closes a remote code execution vulnerability affecting sites that process images with the Imagick extension and Ghostscript.
The WordPress security team is urging site owners to update immediately, either through the Dashboard’s Updates screen or by downloading the release directly from WordPress.org, since sites with automatic background updates should already be receiving the patch.
The flaw, tracked as CVE-2026-65640 and detailed in GHSA-8vr3-7mxf-gx8w, was responsibly disclosed by researchers at pwn.ai and allows an authenticated Author-level user to achieve remote code execution through a crafted file upload.
The issue arises from WordPress’s reliance on ImageMagick to resize and process Media Library images.