Threat Advisory

WordPress Imagick RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical remote code execution vulnerability, tracked as CVE-2026-65640 with a CVSS score of 9.0, affects WordPress sites that process images with the Imagick extension and Ghostscript. The flaw arises from ImageMagick not stopping at JPEGs and PNGs; it also opens PostScript, EPS, and PDF files, which are then handed off to Ghostscript for rendering. A mismatch in how files get identified allows attackers to plant malicious payloads via XML-RPC's wp.uploadFile method or the cover-art extraction routine for uploaded MP3 files, both of which write bytes directly without content inspection. This vulnerability is exploitable by an authenticated Author-level user and requires a crafted file upload. The business impact is significant, particularly on multi-author publications, membership platforms, and client sites with open or loosely managed contributor access, as any Author can attempt to upload a booby-trapped file disguised as an image.

RECOMMENDATION:

We recommend you to update WordPress to version 7.0.4.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

A critical remote code execution vulnerability, tracked as CVE-2026-65640 with a CVSS score of 9.0, affects WordPress sites that process images with the Imagick extension and Ghostscript. The flaw arises from ImageMagick not stopping at JPEGs and PNGs; it also opens PostScript, EPS, and PDF files, which are then handed off to Ghostscript for rendering. A mismatch in how files get identified allows attackers to plant malicious payloads via XML-RPC's wp.uploadFile method or the cover-art extraction routine for uploaded MP3 files, both of which write bytes directly without content inspection. This vulnerability is exploitable by an authenticated Author-level user and requires a crafted file upload. The business impact is significant, particularly on multi-author publications, membership platforms, and client sites with open or loosely managed contributor access, as any Author can attempt to upload a booby-trapped file disguised as an image.

RECOMMENDATION:

We recommend you to update WordPress to version 7.0.4.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu