WordPress has just released a security-focused update — version 7.0.4 — to close a remote code execution flaw that can be triggered when images are processed with the Imagick extension and Ghostscript. The vulnerability, tracked as CVE-2026-65640 and described in GHSA-8vr3-7mxf-gx8w, was responsibly disclosed by researchers at pwn.ai. While exploitation requires an authenticated Author-level account or higher, the bug’s mechanics
