WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
WordPress shipped 7.0.4 on August 12, a security release the core team says to install at once. It closes a single flaw, tracked as CVE-2026-65640, that let a logged-in author turn an ordinary-looking image upload into code running on the server. The mechanism is an old one returning under a new name: a file called that is not really a PNG at all. The catch that keeps it from being a five-alarm…
评论
?
参与讨论