WordPress CVE-2026-65640: Why 7.0.4 is not an optional update

Back

Quick reality check: WordPress 7.0.4 shipped on 12 August 2026 — not a feature release, a security fix. CVE-2026-65640 (GHSA-8vr3-7mxf-gx8w) is remote code execution through a file upload. The prerequisites are an Author or higher account plus Imagick and Ghostscript on the server. That stack is still sitting on a lot of VPS boxes.

WordPress rates it High (CVSS 8.8). Cloudflare named the WAF rule after this CVE on 17 August. If you are on 7.0.3 or an unpatched 6.x / 5.x / 4.7 branch, you owe the update — not “sometime in the next maintenance window”.

What happened

pwn.ai reported the issue. WordPress published 7.0.4 on 12 August and backported the fix as a courtesy all the way to the 4.7 branch. Only the current major version is actively supported. The backports exist so old sites are not left open — they are not a licence to stay on 5.8 forever.

The attack needs a logged-in account with upload rights, not a guest on the frontend. Author accounts on community blogs, guest editors and leftover staff logins are the practical path, not “some bot from the internet”.

Which version you need

  • 7.0.x7.0.4
  • 6.9.x6.9.7
  • 6.8.x6.8.8
  • Older branches: the latest minor from 4.7.35 upward — or better, go straight to 7.0.4.

Dashboard → Updates → Update Now. Sites with background auto-updates will pull 7.0.4 themselves. Self-managed VPS often will not.

Checklist for VPS and root customers

  1. Check the version. Admin or wp core version. If you see 7.0.3 or older on the same branch — patch now.
  2. Backup before you click. Files plus database. A security update is small. A broken plugin after it is not.
  3. Apply the update. Core first. Plugins and themes after, not the other way around.
  4. Clean up Author accounts. Anyone with upload_files matches the advisory’s prerequisite. No shared Author logins, no leftover guest access.
  5. Imagick/Ghostscript only if you need them. Many stacks have both “because default”. If you do not need PDF or Postscript previews, harden that chain instead of leaving it on forever.
  6. A WAF is not a patch. Cloudflare blocks known patterns. The fix lives in WordPress. Both is good. WAF alone is not a patch.

What we will not do here

No PoCs, no upload recipes. If you run a site, you need the version and the roles — not a walkthrough of the bug. After the update: a short check that the admin still loads and no unknown plugins appeared.

WordPress on a Frankfurt VPS means you decide when it gets patched. Shared hosts often do it for you. Root does it only when you start it.

Order a V-Server →
Linux root server · WordPress 7.0.4 release

More blog articles

We are excited to expand our gameserver portfolio. Five new games are now available: Enshrouded Soulmask Nightingale HumanitZ The Front Necesse Windrose Foundry All titles are ready to book and benefit...

Hetzner is raising prices – but your gameplay doesn't have to suffer Hetzner has announced price adjustments. For many customers, this is annoying – but for gamers who rely on stable, high-performance game servers, it's a real wake-up call. When your c...

First Hetzner, now OVH: Game server hosting prices are skyrocketing. For gamers, it's time to consider alternatives. The Price Spiral Is Turning OVH founder Octave Klaba recently confirmed: Prices for RAM, CPUs, and storage have exploded. OVH is now paying s...