VORANT. Threat Intelligence Sign in Get the full feed

WordPress patches remote code execution flaw

routine vulnerability technology

WordPress versions before 7.0.4 contain a vulnerability allowing remote arbitrary code execution; users should update immediately.

The French national cybersecurity agency (ANSSI/CERT-FR) issued an advisory regarding a vulnerability in WordPress affecting all versions prior to 7.0.4. The flaw, tracked as CVE-2026-65640, allows an attacker to achieve remote arbitrary code execution on affected systems, posing a significant risk to any website or platform running the vulnerable software.

WordPress addressed the issue in its 7.0.4 release published on August 12, 2026. No details are provided regarding active exploitation in the wild; the advisory is a standard vendor-patch notification recommending administrators apply the official fix promptly given the wide deployment of WordPress across websites globally.

Mentioned in this report

Vulnerabilities CVE-2026-65640

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1018

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free