Source: wordpress Version: 7.0.3+dfsg1-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for wordpress. CVE-2026-65640[0]: | WordPress is vulnerable to a remote code execution vulnerability via | malicious Postscript file upload by an Author level user or higher. | Prerequisites: * Imagick and Ghostscript in use on the server * A | malicious user with the `upload_files` capability This issue | affects all versions of WordPress. Version 7.0.4 has been released, | containing a fix for the vulnerability, and as a courtesy to users | on older branches the fix has been backported to all branches back | to 4.7. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-65640 https://www.cve.org/CVERecord?id=CVE-2026-65640 [1] https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ [2] https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w Please adjust the affected versions in the BTS as needed. Regards, Salvatore

