WordPress 7.0.4: Author-level Postscript upload RCE (CVE-2026-65640)
WordPress 7.0.4 patches CVE-2026-65640, an Author-level Postscript upload RCE when Imagick and Ghostscript are present. See who is affected and what to do.
Read articleNew24/7 monitoring and daily cloud backups now included in every Shield Pro plan.
Blog
Product updates, WordPress advice, and stories from behind the shield.
WordPress 7.0.4 patches CVE-2026-65640, an Author-level Postscript upload RCE when Imagick and Ghostscript are present. See who is affected and what to do.
Read articleA WordPress plugin supply chain attack hit BdThemes in August 2026. See which plugins were affected, how hidden admins were created, and how to check your site.
Read articleWordPress XSS2Shell (CVE-2026-64638) is a login XSS that can lead to RCE. See who is at risk, which versions are patched, and check your site with our free tool.
Read articleWordPress security is not only plugins and scans. Optional authenticator 2FA and Active Sessions help lock down the BugShield account that holds your sites and vault.
Read article