Liquid Web Status · History · Incident #6359

ACTIVE INCIDENT

Security Advisory: WordPress Security Update for CVE-2026-65640

Minor · Started Aug 12, 2026 · 11:44 AM

  • Duration

    Ongoing

  • Severity

    Minor

  • Detection lead

  • User reports

Summary

Security Advisory: WordPress Security Update for CVE-2026-65640

A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript. The vulnerability has been addressed through updates across supported WordPress branches. Patched Versions: Customers should update to the following patched version for their respective WordPress branch: 7.0.4 6.9.7 6.8.8 6.7.7 6.6.7 6.5.10 6.4.10 6.3.10 6.2.11 6.1.12 6.0.14 5.9.16 5.8.15 5.7.17 5.6.19 5.5.20 5.4.21 5.3.23 5.2.26 5.1.24 5.0.27 4.9.31 4.8.30 4.7.35 Recommended Action: Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate. Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please reach us via live chat or via a case. Additional information: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w


  • Started

    Aug 12, 2026 · 11:44 AM

  • Status

    Investigating

  • Duration

    Ongoing

  • Severity

    None

Event timeline

How this incident unfolded

  • Investigating

    Aug 12 · 11:44 AM Liquid Web

    A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript. The vulnerability has been addressed through updates across supported WordPress branches. Patched Versions: Customers should update to the following patched version for their respective WordPress branch: 7.0.4 6.9.7 6.8.8 6.7.7 6.6.7 6.5.10 6.4.10 6.3.10 6.2.11 6.1.12 6.0.14 5.9.16 5.8.15 5.7.17 5.6.19 5.5.20 5.4.21 5.3.23 5.2.26 5.1.24 5.0.27 4.9.31 4.8.30 4.7.35 Recommended Action: Customers are strongly encouraged to update WordPress core to the latest available patched version and ensure automatic updates are enabled where appropriate. Customers with automatic updates enabled should receive the applicable update automatically. However, we recommend verifying the currently running WordPress version to ensure the security update has been successfully applied. We will continue to monitor the situation and provide further updates if required. If you need assistance or have any concerns, please reach us via live chat or via a case. Additional information: https://wordpress.org/news/2026/08/wordpress-7-0-4-release/ https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w

Get alerted before the next Liquid Web outage.

Pulsetic catches degradations minutes before vendors acknowledge them.