WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.
We have discovered 7,982,646 live websites that are affected by CVE-2026-65640.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 7,982,646 live websites (100% of WordPress install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 1,384 versions ( 93% of all versions) |
| 2,514,620 websites | |
| 809,195 websites | |
| 468,296 websites | |
| 350,408 websites | |
| 344,215 websites | |
| 312,276 websites | |
| 255,328 websites | |
| 203,560 websites | |
| 203,058 websites | |
| 196,253 websites |
| .com | 3,445,220 websites |
| .de | 513,332 websites |
| .org | 409,162 websites |
| .net | 236,135 websites |
| .nl | 221,279 websites |
| .it | 212,922 websites |
| .co.uk | 196,593 websites |
| .ru | 171,101 websites |
| .pl | 153,011 websites |
| .fr | 148,965 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | ** | ||
| ********.*********.com | ** | ||
| ***************.org | *** | ||
| ******.net | *** | ||
| ************.org | *** | ||
| *****************.com | *** | ||
| ****.br | *** | ||
| **********.com | *** | ||
| *********.de | *** | ||
| ****.io | *** |
FAQ