WordPress released a WordPress security update on August 12, 2026 that patches a high-severity remote code execution flaw affecting sites still running version 7.0.3 or earlier. If your business website runs on WordPress and uses the Imagick PHP extension with Ghostscript for image handling, or if multiple people have Author-level accounts, update it now. The fix already exists, so there is no reason to wait for your next website check-in.
- WordPress 7.0.4, released August 12, 2026, fixes CVE-2026-65640, a high-severity flaw with a CVSS score of 8.8 out of 10.
- The bug lets an authenticated Author-level (or higher) user upload a malicious file and run arbitrary code on the server.
- It affects installs from WordPress 4.7.0 through 7.0.3 that have Imagick and Ghostscript enabled for image processing, and the fix was backported all the way to version 4.7.
- WordPress still runs roughly two out of every five websites worldwide, according to Search Engine Journal’s market share reporting, so this touches a lot of small business sites.
- A missed website patch carries the same risk as a missed Windows patch: an open door an attacker doesn’t have to work hard to find.
Do I need to update WordPress right now?
If your site is self-hosted or managed by an outside web agency rather than a fully managed WordPress host, yes. Log into the WordPress dashboard, check the version number under Updates, and apply the patch if you’re on 7.0.3 or earlier. Even if your specific setup doesn’t use Imagick, staying current closes off this vulnerability and whatever else gets fixed alongside it.
What is CVE-2026-65640 and who is actually at risk?
The vulnerability was discovered in how Ghostscript handles certain embedded PostScript files when WordPress uses Imagick for image processing. An attacker who already has Author-level access, which is a lower permission tier than Administrator, could upload a crafted file and execute code on the server. That means the biggest risk sits with sites that have several contributor or author accounts, including guest bloggers, part-time marketing help, or old accounts nobody remembered to remove. The WordPress security advisory notes the flaw only affects installations with Imagick and Ghostscript enabled, a common combination on shared hosting plans that support image editing plugins.
Does my web host handle this automatically?
It depends entirely on how your site is hosted. Fully managed WordPress hosts often push core security releases within a day or two without you doing anything. If your site sits on general-purpose shared hosting, a VPS, or was set up by a web designer who isn’t actively maintaining it, the update is probably sitting there waiting for someone to click the button. If you don’t know which category your site falls into, that’s worth a five-minute phone call to whoever hosts it. This is the same blind spot that shows up in regular patch management for servers and workstations, just applied to the website instead.
What else should a Southwest Florida business check when patching a website?
Back up the site before applying any update, even a security-only one. Then review who actually has Author or Administrator access. It’s common for a site to accumulate old logins from a former employee, a past marketing contractor, or a developer who finished a project two years ago and never got removed. The same discipline that goes into an IT asset inventory for laptops and servers applies here: know what plugins are installed, who can log in, and when each was last updated. A website with ten inactive plugins and three forgotten user accounts is a much bigger target than one that’s been kept lean.
Frequently asked questions
Is my website affected if I don’t use Imagick?
No. The flaw only applies to installs using the Imagick PHP extension together with Ghostscript for image processing. If that combination isn’t enabled on your site, you’re not exploitable through this specific bug, though updating is still good practice.
Do I need technical skills to update WordPress?
No. Most sites can update from the WordPress admin dashboard under Updates, and many hosts push the update automatically. If you’re not sure who is responsible for your site’s core updates, that’s worth figuring out today rather than after something breaks.
How urgent is this compared to other IT patches?
A CVSS score of 8.8 out of 10 puts it in the high-severity range, and a public fix is already out, which tends to speed up attacker interest in the underlying flaw. Treat it with the same urgency as an important Windows or Microsoft 365 security patch.
What if my website hasn’t been updated in years?
Back it up first, then update core, themes, and plugins in that order, ideally through a staging copy if your host offers one. A site that’s been neglected for years usually carries more than just this one vulnerability, so a fuller review is worth the time.
If you’re not sure whether your website, servers, or Microsoft 365 environment are current on security patches, we’ll take a look. Southwest Florida IT offers a free 15-minute IT and security review for local businesses. Contact us to get on the calendar.
Southwest Florida IT