WordPress 7.0.4 Patches Remote Code Execution Vulnerability

https://www.securityweek.com/wp-content/uploads/2024/08/WordPress.jpeg

WordPress on Wednesday announced patches for a high-severity vulnerability that allows authenticated attackers to execute arbitrary code remotely.

Tracked as CVE-2026-65640 (CVSS score of 8.8), the security defect can be exploited by attackers with Author-level user or higher permissions via malicious Postscript file uploads.

According to WordPress’ advisory, the issue affects only installations that use Imagick and Ghostscript, as it was discovered in Ghostscript’s handling of certain embedded files. Successful exploitation requires that an attacker has file upload rights.

“WordPress version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches, the fix has been backported to all branches back to 4.7,” the web content management system’s maintainers announced.

The vulnerability resides in how ImageMagick (through the Imagick extension) and WordPress handle various types of files: ImageMagick looks at the contents, while WordPress looks at the file extension, vulnerability management...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/MB6pJa8ZzL8fom8JKMHzwV-1590-80.jpg

Quote of the day by Motorola's cell phone pioneer Martin Cooper: 'People want to talk to other people — not a house, or an office, or a car' — blueprinting the start of a new era of communications

The American engineer Mark Cooper is considered one of the leading pioneers of the wireless communications industry, envisioning a world in which people would communicate wherever they were and not from fixed locations. Without his work in the mid-20th century, the mobile communications industry would arguably be non-existent. Hello Moto