WordPress CVE-2026-65640: Why 7.0.4 is not an optional update
Back
Quick reality check: WordPress 7.0.4 shipped on 12 August 2026 — not a feature release, a security fix. CVE-2026-65640 (GHSA-8vr3-7mxf-gx8w) is remote code execution through a file upload. The prerequisites are an Author or higher account plus Imagick and Ghostscript on the server. That stack is still sitting on a lot of VPS boxes.
WordPress rates it High (CVSS 8.8). Cloudflare named the WAF rule after this CVE on 17 August. If you are on 7.0.3 or an unpatched 6.x / 5.x / 4.7 branch, you owe the update — not “sometime in the next maintenance window”.
What happened
pwn.ai reported the issue. WordPress published 7.0.4 on 12 August and backported the fix as a courtesy all the way to the 4.7 branch. Only the current major version is actively supported. The backports exist so old sites are not left open — they are not a licence to stay on 5.8 forever.
The attack needs a logged-in account with upload rights, not a guest on the frontend. Author accounts on community blogs, guest editors and leftover staff logins are the practical path, not “some bot from the internet”.
Which version you need
- 7.0.x → 7.0.4
- 6.9.x → 6.9.7
- 6.8.x → 6.8.8
- Older branches: the latest minor from 4.7.35 upward — or better, go straight to 7.0.4.
Dashboard → Updates → Update Now. Sites with background auto-updates will pull 7.0.4 themselves. Self-managed VPS often will not.
Checklist for VPS and root customers
- Check the version. Admin or
wp core version. If you see 7.0.3 or older on the same branch — patch now. - Backup before you click. Files plus database. A security update is small. A broken plugin after it is not.
- Apply the update. Core first. Plugins and themes after, not the other way around.
- Clean up Author accounts. Anyone with
upload_filesmatches the advisory’s prerequisite. No shared Author logins, no leftover guest access. - Imagick/Ghostscript only if you need them. Many stacks have both “because default”. If you do not need PDF or Postscript previews, harden that chain instead of leaving it on forever.
- A WAF is not a patch. Cloudflare blocks known patterns. The fix lives in WordPress. Both is good. WAF alone is not a patch.
What we will not do here
No PoCs, no upload recipes. If you run a site, you need the version and the roles — not a walkthrough of the bug. After the update: a short check that the admin still loads and no unknown plugins appeared.
WordPress on a Frankfurt VPS means you decide when it gets patched. Shared hosts often do it for you. Root does it only when you start it.
Order a V-Server →
Linux root server ·
WordPress 7.0.4 release
More blog articles
We are excited to expand our gameserver portfolio. Five new games are now available: Enshrouded Soulmask Nightingale HumanitZ The Front Necesse Windrose Foundry All titles are ready to book and benefit...
Hetzner is raising prices – but your gameplay doesn't have to suffer Hetzner has announced price adjustments. For many customers, this is annoying – but for gamers who rely on stable, high-performance game servers, it's a real wake-up call. When your c...
First Hetzner, now OVH: Game server hosting prices are skyrocketing. For gamers, it's time to consider alternatives. The Price Spiral Is Turning OVH founder Octave Klaba recently confirmed: Prices for RAM, CPUs, and storage have exploded. OVH is now paying s...