
WordPress Imagick RCE Analysis: ImageTragick's Return
WordPress Imagick RCE is back, and this time it’s a patched authenticated flaw that echoes the infamous 2016 ImageTragick bug family. Tracked as CVE-2026-65640, this CVSS 8.8 HIGH vulnerability allows an Author-level account to achieve remote code execution on sites running the Imagick PHP extension with Ghostscript. If you are looking for how to fix WordPress Imagick Ghostscript RCE vulnerability, the answer starts with updating to 7.0.4 or a backported branch immediately. This deep dive breaks down the root cause, the exact attack path, and the remediation steps you need to secure your infrastructure.
How This Was Researched
This analysis cross-references the GitHub Security Advisory GHSA-8vr3-7mxf-gx8w with the official WordPress 7.0.4 release notes and coverage from SecurityWeek, CyberSecurityNews, GBHackers, and SecurityOnline. We verified the fix commit details against the advisory and release timeline. We did not perform hands-on exploit testing, and no in-the-wild indicators of compromise are known. This analysis is based on official advisories and published research — we did not run the exploit hands-on. Last researched: August 2026.
What Is CVE-2026-65640?
CVE-2026-65640 is an authenticated remote code execution vulnerability in WordPress’s Imagick image handling, requiring an account with the upload_files capability (Author role or higher). The flaw carries a CVSS 3.0 score of 8.8 HIGH with the vector AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and maps to CWE-434 (Unrestricted Upload of File with Dangerous Type) per the official advisory. As of 2026-08-15, this CVE is not in CISA KEV and has no known in-the-wild exploitation. The CVE.org record remains in RESERVED state, and NVD has not published it.
Root Cause: Why ImageMagick Trusted the Filename
The vulnerability lives in WP_Image_Editor_Imagick::load() within wp-includes/class-wp-image-editor-imagick.php. The code trusted the file’s extension to determine its type rather than inspecting the actual binary content. ImageMagick, however, identifies the real format by content sniffing. When it encounters PostScript, EPS, or PDF input, it delegates rendering to Ghostscript, which executes embedded PostScript code. This is the same trust boundary failure that produced the 2016 ImageTragick (CVE-2016-3714) vulnerabilities. An attacker who can upload a file with a benign extension like .png but containing PostScript payload content can trigger code execution because the editor never validates what the bytes actually are, as detailed in the GitHub advisory.
The Attack Path: Author Account to Server-Side Code Execution
To exploit this, three conditions must align: the Imagick PHP extension is active, Ghostscript is installed, and an attacker holds an account with upload capability. The primary upload path through the Media Library is protected by wp_check_filetype_and_ext(), which validates extensions and MIME types. However, two alternate paths bypass this check entirely: the XML-RPC wp.uploadFile method and MP3 cover-art extraction. Both write bytes directly via wp_upload_bits(), skipping content inspection. Once a malicious file lands, ImageMagick processes it, Ghostscript executes the embedded PostScript, and the attacker achieves RCE as the web-server user. From there, the impact chain includes reading wp-config.php for database credentials and salts, exfiltrating data, deploying webshells, defacing the site, and pivoting to internal infrastructure. Multi-author blogs, membership platforms, client portals, and agency-managed sites face the highest risk.
MITRE ATT&CK Mapping (Analyst Suggestion)
No vendor-published MITRE ATT&CK mapping exists for CVE-2026-65640. As an analyst suggestion, the following techniques apply: T1190 (Initial Access via Exploit Public-Facing Application), T1059.004 (Execution via Unix Shell), and T1505.003 (Persistence via Web Shell). Treat this as a working hypothesis, not an official reference, until MITRE or WordPress publishes a definitive mapping.
What the 7.0.4 Fix Changed (Commit 7daaa50)
The fix, commit 7daaa50, addresses the root cause by scanning the first chunk of every upload for dangerous content signatures. Specifically, it blocks PostScript and EPS file signatures, rejects fake PDFs that lack a genuine %PDF- header, filters gzip and bzip2 compressed wrappers, and neutralizes format-prefix tricks like EPS:innocent.png that previously confused ImageMagick’s content detection. This content-based validation now runs on all upload paths, closing the XML-RPC and MP3 cover-art bypasses. The patch shipped in WordPress 7.0.4 and was backported to every maintenance branch down to 4.7.35, ensuring broad coverage across the supported ecosystem.
How Do You Fix the WordPress Imagick Ghostscript RCE Vulnerability?
Fixing this vulnerability requires a tiered approach. First and foremost, update WordPress to 7.0.4 or the appropriate backported branch for your current version — this is the only complete mitigation. If an immediate update is impossible, apply compensating controls: disable XML-RPC entirely (it is not needed for the vast majority of sites), restrict the upload_files capability to trusted users only, and remove Ghostscript from the server or edit ImageMagick’s policy.xml to disable the PS, EPS, and PDF coders. After updating, scan your uploads directory for webshells, audit all Author-level and higher accounts for suspicious activity, and review server logs for ghostscript processes spawned by PHP. If you suspect compromise, rotate all database credentials, salts, and API keys immediately, as detailed in the official release notes. For ongoing tracking, browse our CVE database for related advisories.
FAQ
This FAQ answers the questions defenders asked most about CVE-2026-65640 this week. Each answer is self-contained, so you can skim straight to the section you need. If you are weighing a patch window, start with the exploitation status and affected-versions answers before deciding on your timeline.
Is CVE-2026-65640 Being Exploited in the Wild?
As of 2026-08-15, there is no known in-the-wild exploitation of CVE-2026-65640, and the CVE is not listed in CISA KEV, according to the GitHub Security Advisory. This could change quickly, so treat the patch as urgent rather than optional. Continue monitoring threat feeds and WordPress security announcements for any updates on active exploitation.
Do I Need Both the Imagick Extension and Ghostscript to Be Vulnerable?
Yes, both the Imagick PHP extension and Ghostscript must be present for CVE-2026-65640 to be exploitable, as confirmed by the advisory’s affected configuration. Removing either component breaks the attack chain. If you cannot patch immediately, disabling Ghostscript or removing it from the server is a highly effective interim mitigation that neutralizes the payload execution step.
Which WordPress Versions Are Affected by CVE-2026-65640?
WordPress versions 4.7.0 through 7.0.3 are affected, with the fix released in 7.0.4 and backported to 4.7.35 and every maintenance branch in between, per the WordPress release notes. If your site runs any version in that range, you must update to the nearest patched branch. Older versions outside this range are either unsupported or not vulnerable to this specific flaw.
For related analysis, see our coverage of the N-able N-central authentication bypass and the pgAdmin 4 command injection flaw, both of which share similar attack surface considerations. You can also explore the FortiSandbox unauthenticated RCE for a contrasting case of a zero-privilege exploit.
📖 Related Reads
- ToolBrain — tool reviews, LLM comparisons, and AI workflow guides
Cross-links automatically generated from None.