Source: wordpress
Version: 7.0.3+dfsg1-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for wordpress.

CVE-2026-65640[0]:
| WordPress is vulnerable to a remote code execution vulnerability via
| malicious Postscript file upload by an Author level user or higher.
| Prerequisites: * Imagick and Ghostscript in use on the server * A
| malicious user with the `upload_files` capability  This issue
| affects all versions of WordPress. Version 7.0.4 has been released,
| containing a fix for the vulnerability, and as a courtesy to users
| on older branches the fix has been backported to all branches back
| to 4.7.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-65640
    https://www.cve.org/CVERecord?id=CVE-2026-65640
[1] https://wordpress.org/news/2026/08/wordpress-7-0-4-release/
[2] 
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to