Get a .BG domain for only €25.94 per year when ordered with hosting.

Get a free gift mug with selected hosting plans!

WordPress 7.0.4: A Critical Security Fix and What It Means for You

Георги Димитров Георги Димитров 5 min read
WordPress 7.0.4: A Critical Security Fix and What It Means for You
Summarize this article with: Summarize with:

On 12 August 2026, just six days after the previous update, the WordPress team released a new version, WordPress 7.0.4. This is once again a security-focused update.

This time there is only one issue, but it is among the most serious kinds: under certain conditions it allows someone else’s code to be executed on your server. The good news is that the fix is already available and quick and easy to apply. In this article we explain briefly what happened and what the next steps are, without unnecessary technical details.

In short

On 12 August 2026, WordPress 7.0.4 was released with a fix for one high-severity vulnerability (CVE-2026-65640, scored 8.8 out of 10). Every version from 4.7 up to and including 7.0.3 is affected, which means even sites updated only a few days ago. We recommend updating yours to version 7.0.4 without delay. If you need help, the Jump.bg team is here for you.

What happened

The new version fixes a single vulnerability in the WordPress core. Unlike most of the issues in the previous update, this one is not limited to the content of the site — it affects the server itself. Here are the essentials in plain language:

Detail Value
Identifier CVE-2026-65640 (GHSA-8vr3-7mxf-gx8w)
What it could allow Running someone else’s code on the server by uploading a specially crafted file.
Risk score 8.8 out of 10, i.e. high
Who could use it A registered user with the Author role or higher
Additional condition The server processes images with Imagick together with Ghostscript
Affected versions From 4.7 up to and including 7.0.3

In short, the attacker uploads a file to the media library that looks harmless but contains hidden instructions. When WordPress tries to process that file in order to create a scaled copy, those instructions can be executed by the server. From that point on the risk is serious, because it reaches not only the content but the data of the site as well.

The requirement that the attacker holds the Author role sounds reassuring, but it should not be underestimated. If your site allows registrations, if you work with external authors, or if you have old accounts that are no longer in use, that condition is easier to meet than it looks. Updating to 7.0.4 removes the risk entirely, so that is all you need to do to be safe.

The issue was responsibly reported by the team at pwn.ai. Full technical information is available in the official WordPress announcement.

Is my site affected?

As with the previous update, the scope is very broad and covers releases spanning nearly ten years:

WordPress version Affected? What to do
7.0.4 No No action required
From 4.7 to 7.0.3 Yes Update to 7.0.4
4.6 and earlier Yes, and no longer receives fixes Contact us about a migration

Please note that the update to 7.0.3 from a few days ago is not enough. If you already applied it, one more step to 7.0.4 is needed.

If for some reason you cannot move to 7.0.4 straight away, WordPress is also releasing fixes for the older branches, for example 6.9.7, 6.8.8 and 6.7.7. These are shipping gradually over the coming hours and days. That is a good temporary solution, but it is not a substitute for updating to the current version.

There is no need to check whether your server uses Imagick and Ghostscript. That combination is widespread in hosting environments, and checking takes longer than the update itself. If you are not sure which version you are using, you can find it in the WordPress admin area, in the bottom right corner of the screen or under Dashboard → Updates.

Why it is a good idea to act now

Because the fix is already public, information about the vulnerability is available to malicious actors as well. Issues of this kind are especially attractive for automated attacks, because they give access to the server itself and not only to the content. The good news is that updating takes only a few minutes and removes the risk entirely.

What to do

Updating WordPress takes only a few minutes. Follow these simple steps:

  1. Create a backup of your site. This is good practice before any update.
  2. Log in to the WordPress admin area.
  3. Open Dashboard → Updates.
  4. If an update is available, click Update Now.
  5. Make sure the version is now 7.0.4.

In many cases WordPress applies important security updates automatically, but it is a good idea to check manually as well, so you can be sure your site is protected.

Because this issue requires an account with permission to upload files, take a few minutes for Users → All Users as well. Remove the accounts that are no longer in use, and move to a lower role those that do not need to upload files. If your site accepts open registrations, check which role new users are given.

Need help?

If you are not sure which version you are using, run into difficulties with the update, or simply want someone to check that everything is fine, the Jump.bg support team is here to help. Contact us and we will guide you step by step.

If you are still choosing where to host your site, take a look at our WordPress hosting plans. They are fast, secure and backed by expert support, so you can focus on your business.

Your site’s security matters to us. If you have any questions, contact the Jump.bg team. We are here to help.

Enjoyed the article? Share it:
Георги Димитров
Article from

Георги Димитров

Георги Димитров прекарва над 10 години в това да прави сайтовете бързи, сигурни и надеждни. Помогнал е на десетки български и международни компании да изградят успешни онлайн проекти, от малки електронни магазини до сложни уеб приложения. В блога на Jump.bg пише за WordPress без излишен технически жаргон, с практични съвети за сигурност, производителност и поддръжка, еднакво полезни за начинаещи и за професионалисти.

More articles

Follow us:

Subscribe to our newsletter

With your subscription, you get more up-to-date news and our special promo offers

Subscribe to our newsletter