WordPress 7.0.4 Security Release: Update Immediately to Fix Remote Code Execution Vulnerability

WordPress 7.0.4 Security Release

WordPress has officially released WordPress 7.0.4, a critical security update addressing a severe vulnerability. Site administrators are strongly urged to update their installations immediately to keep their web properties safe.

The security patch resolves an Authenticated Author+ Remote Code Execution (RCE) vulnerability triggered via malicious file uploads on servers running Imagick and Ghostscript (tracked as CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w). The flaw was responsibly reported by security researchers at pwn.ai.

Alongside version 7.0.4, security backports are being rolled out across older supported branches down to WordPress 4.7.

Affected versions: <7.0.4, < 6.9.7, <6.8.8

Source: Wordpress News