Angaben zum Datum
Datum aus der Quelle.
Erstmals gesehen am .
Wordpress von Automattic
WordPress 7.0.4 – Sicherheitsupdate
WordPress 7.0.4 behebt eine Sicherheitslücke, bei der authentifizierte Nutzer ab Author-Rolle über einen schädlichen Datei-Upload auf Sites mit Imagick und Ghostscript Remote Code Execution auslösen konnten.
WordPress 7.0.4 is now available
WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately.
You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard → Updates and clicking Update Now. Sites that support automatic background updates will begin updating shortly.
For more information, please visit the WordPress 7.0.4 HelpHub site.
Security update included in this release
The security team would like to thank the team at pwn.ai for responsibly reporting the following vulnerability and allowing it to be fixed in this release:
- Authenticated Author+ remote code execution via malicious file upload on sites that use Imagick and Ghostscript.
Backports
As a courtesy, these fixes are being backported through to the 4.7 branch and the 7.1 RC3 release that’s due later today. As a reminder, only the most recent version of WordPress is actively supported. The backports are in progress and will ship as they become ready.
CVE and GHSA references
Further details can be found in the advisory: CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w.