WordPress 7.0.4 Patched: Critical Remote Code Execution Vulnerability in Imagick

WordPress 7.0.4 is now available as a critical security release.

The update addresses a vulnerability where authenticated users with Author+ capabilities can execute remote code on sites utilizing Imagick and Ghostscript. The attack vector involves malicious file uploads.

WordPress recommends updating immediately. You can update via the Dashboard (Updates) or by downloading the package from WordPress.org. Automatic background updates will handle this for supported sites.

The security team credits pwn.ai for the responsible disclosure. The fix is also backported to the 4.7 branch and WordPress 7.1 RC3.

CVE Reference: CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w