WordPress patches remote code execution flaw
WordPress versions before 7.0.4 contain a vulnerability allowing remote arbitrary code execution; users should update immediately.
The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory regarding a vulnerability in WordPress affecting all versions prior to 7.0.4. The flaw, tracked as CVE-2026-65640, allows an attacker to achieve remote arbitrary code execution on affected systems, posing a significant risk to any website or platform running the vulnerable software.
WordPress addressed the issue in its 7.0.4 release published on August 12, 2026. No details are provided regarding active exploitation in the wild; the advisory is a standard vendor-patch notification recommending administrators apply the official fix promptly given the wide deployment of WordPress across websites globally.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1018
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free