{"id":"BIT-wordpress-multisite-2026-65640","details":"WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher.\n\nPrerequisites:\n* Imagick and Ghostscript in use on the server\n* A malicious user with the `upload_files` capability\n\nThis issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.","aliases":["BIT-wordpress-2026-65640","CVE-2026-65640"],"modified":"2026-08-21T09:26:00.336232746Z","published":"2026-08-21T08:58:11.209Z","database_specific":{"severity":"High","cpes":["cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*"]},"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65640"},{"type":"WEB","url":"https://wordpress.org/news/2026/08/wordpress-7-0-4-release/"}],"affected":[{"package":{"name":"wordpress-multisite","ecosystem":"Bitnami","purl":"pkg:bitnami/wordpress-multisite"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"7.0.4"}]}],"database_specific":{"source":"https://github.com/bitnami/vulndb/tree/main/data/wordpress-multisite/BIT-wordpress-multisite-2026-65640.json"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}],"schema_version":"1.9.0"}