Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN845
_____________________________________________________________________

DATE                : 17/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running WordPress versions prior to
                  7.0.4, 6.9.7, 6.8.8, 6.7.7, 6.6.7, 6.5.10, 6.4.10,
             6.3.10, 6.2.11, 6.1.12, 6.0.14, 5.9.16, 5.8.15, 5.7.17,
             5.6.19, 5.5.20, 5.4.21, 5.3.23, 5.2.26, 5.1.24, 5.0.27,
                             4.9.31, 4.8.30, 4.7.35.
 
=====================================================================
https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-8vr3-7mxf-gx8w
_____________________________________________________________________

Remote code execution vulnerability via malicious file upload by an
Author level user or higher
High
johnbillion published GHSA-8vr3-7mxf-gx8w 

Package
WordPress (WordPress)

Affected versions
7.0.0 - 7.0.3
6.9.0 - 6.9.6
6.8.0 - 6.8.7
6.7.0 - 6.7.6
6.6.0 - 6.6.6
6.5.0 - 6.5.9
6.4.0 - 6.4.9
6.3.0 - 6.3.9
6.2.0 - 6.2.10
6.1.0 - 6.1.11
6.0.0 - 6.0.13
5.9.0 - 5.9.15
5.8.0 - 5.8.14
5.7.0 - 5.7.16
5.6.0 - 5.6.18
5.5.0 - 5.5.19
5.4.0 - 5.4.20
5.3.0 - 5.3.22
5.2.0 - 5.2.25
5.1.0 - 5.1.23
5.0.0 - 5.0.26
4.9.0 - 4.9.30
4.8.0 - 4.8.29
4.7.0 - 4.7.34

Patched versions
7.0.4
6.9.7
6.8.8
6.7.7
6.6.7
6.5.10
6.4.10
6.3.10
6.2.11
6.1.12
6.0.14
5.9.16
5.8.15
5.7.17
5.6.19
5.5.20
5.4.21
5.3.23
5.2.26
5.1.24
5.0.27
4.9.31
4.8.30
4.7.35


Description

Certain installations of WordPress are vulnerable to a remote code
execution vulnerability via malicious Postscript file upload by an
Author level user or higher.

Prerequisites:

    Imagick and Ghostscript in use on the server (the weakness is
in Ghostscript's handling of certain embedded files)
    A malicious user with the upload_files capability

WordPress version 7.0.4 has been released, containing a fix for
the vulnerability, and as a courtesy to users on older branches
the fix has been backported to all branches back to 4.7.

Discovered and responsibly disclosed by the team at pwn.ai.


Severity
High
8.8/ 10

CVSS v3 base metrics
Attack vector
Network
Attack complexity
Low
Privileges required
Low
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE ID
CVE-2026-65640

Weaknesses
Weakness CWE-434

=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




