CVE-2026-65640

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisites: * Imagick and Ghostscript in use on the server * A malicious user with the `upload_files` capability This issue affects all versions of WordPress. Version 7.0.4 has been released, containing a fix for the vulnerability, and as a courtesy to users on older branches the fix has been backported to all branches back to 4.7.


We have discovered 7,982,646 live websites that are affected by CVE-2026-65640.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains7,982,646 live websites (100% of WordPress install base)
Vulnerable Versions
  • from 0 through 7.0.4
Vulnerable Versions Count1,384 versions ( 93% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Aug 17, 2026
  • Updated - Aug 18, 2026

Credits

  • Pwn.ai (finder)

Website Distribution by Country

Number of websites using CVE-2026-65640
United States2,514,620 websites



Germany809,195 websites
Japan468,296 websites
GB350,408 websites
France344,215 websites
Italy312,276 websites
Netherlands255,328 websites
Russia203,560 websites
Poland203,058 websites
Spain196,253 websites

Website Distribution by TLD

Number of websites using CVE-2026-65640
.com3,445,220 websites
.de513,332 websites
.org409,162 websites
.net236,135 websites
.nl221,279 websites
.it212,922 websites
.co.uk196,593 websites
.ru171,101 websites
.pl153,011 websites
.fr148,965 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65640

Top websites that are affected by CVE-2026-65640. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*********.com United States**
********.*********.com United States**
***************.org United States***
******.net United States***
************.org Singapore***
*****************.com United States***
****.br Brazil***
**********.com United States***
*********.de Germany***
****.io France***
See full domain list

FAQ

CVE-2026-65640 is Unrestricted Upload of File with Dangerous Type in WordPress
A total of 7,982,646 websites have been identified as vulnerable to CVE-2026-65640, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2026-65640 vulnerability.
WordPress versions up to 7.0.4 are vulnerable to CVE-2026-65640.
CVE-2026-65640 is resolved in version 7.0.4 of WordPress.