WordPress 7.0.4
WordPress 7.0.4 was released on August 12, 2026, as an urgent security release. The WordPress security team recommends that all sites update immediately, and sites with automatic background updates enabled will begin applying the update shortly.
Security Fixes
This release resolves a single, high-severity vulnerability:
- Authenticated Author+ remote code execution via malicious file upload — on sites that use Imagick and Ghostscript, an authenticated user with Author-level access or above could upload a crafted file that leads to remote code execution. The vulnerability is tracked as CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w and was responsibly reported by the team at pwn.ai.
Backports
As a courtesy, the fix is being backported through to the 4.7 branch, and it is also folded into the WordPress 7.1 RC3 build due the same day. Backports ship as they become ready. WordPress reminds users that only the most recent version of the software is actively supported.
Release Notes
The release was led by John Blackbourn, with significant input from Dennis Snell and Jeremy Felt, alongside contributions from a team of core developers and representatives from WP Engine.
How to Update
WordPress 7.0.4 can be downloaded from WordPress.org or applied from the site Dashboard via Updates → Update Now. Given the remote code execution vector, sites on Imagick and Ghostscript stacks — commonly used for image-heavy media libraries — should treat this as a same-day upgrade, not a scheduled one.