Report Incident
× Home DPO CyberHub Rw-CSIRT Website About Rw-CSIRT Alerts Advisories About NCSA Documentation News & Events Topics Contact us Opportunities Privacy Policy

Security Alert: WordPress Remote Code Execution Vulnerability (CVE-2026-65640)

WordPress has released a security update for CVE-2026-65640, also identified as GHSA-8vr3-7mxf-gx8w, a high-severity vulnerability that could allow authenticated users with file-upload permissions to execute malicious code on an affected server.
 
Affected Systems:
 
The following WordPress versions are affected:
 
Security Risks
 
Successful exploitation of this vulnerability could allow an authenticated attacker to execute malicious code through vulnerable Imagick and Ghostscript processing, potentially leading to unauthorized access, data compromise, or further compromise of the WordPress environment.


For the full list of security updates released by WordPress, please refer to the official WordPress security releases.
 
Recommended Actions
 
The National Cyber Security Authority (NCSA) recommends users and system administrators to:
 
1. Update affected WordPress installations as soon as possible to the latest supported versions to address these vulnerabilities and reduce the risk of exploitation.

Upgrade WordPress to the latest supported fixed versions:
 
  • WordPress versions: Upgrade to versions 7.0.4 , 6.9.7, 6.8.8, and 6.7.7, along with the latest supported patch release for earlier versions down to 4.7.35.
 
2. Before updating or patching, please ensure that you have the latest backup that can easily be restored.
 
For further information and support, please contact the National Cyber Security Authority (NCSA) by email to rwcsirt@ncsa.gov.rw or call us on 9009.
 
References

14 August 2026

© 2026 National Cyber Security Authority