What is CVE-2026-65640?
A critical remote code execution (RCE) vulnerability has been discovered in WordPress, allowing Author-level or higher users to execute arbitrary code via malicious Postscript file uploads. This issue affects all WordPress versions where Imagick and Ghostscript are active on the server. It is recommended to restrict users with the `upload_files` capability and disable Ghostscript on the server.
Azərbaycanca: WordPress-də Author və ya daha yuxarı səviyyəli istifadəçi tərəfindən zərərli Postscript faylı yükləməklə uzaqdan kod icrasına (RCE) imkan verən kritik zəiflik aşkarlanıb. Bu boşluq serverdə Imagick və Ghostscript-in aktiv olduğu bütün WordPress versiyalarına təsir edir. `upload_files` icazəsi olan istifadəçiləri məhdudlaşdırmaq və serverdə Ghostscript-i söndürmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: WordPress
FAQ2
What minimum permission level must an attacker have to exploit the CVE-2026-65640 vulnerability in WordPress?
To exploit this vulnerability, an attacker must have at least an Author-level or higher user role.
What are the two main recommended measures to protect against CVE-2026-65640 on a WordPress server?
It is recommended to restrict users with the `upload_files` capability and disable Ghostscript on the server.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.