Risks of Unrestricted File Uploads in WordPress

Published:
Illustrative image about Risks of Unrestricted File Uploads in WordPress

WordPress has published a high-severity vulnerability related to WordPress file uploads without adequate restrictions. This vulnerability could allow for remote code execution if exploited by an attacker with permissions to upload files.

Detected Vulnerability and Exploitation Mechanism

The vulnerability, identified as CVE-2026-65640, is linked to a flaw in Ghostscript, a component that does not securely handle certain embedded files. An attacker with the upload_files capability could upload a malicious Postscript file. This could lead to remote code execution on the affected server.

The issue affects the WordPress file upload function without proper restrictions, making it easier to introduce harmful files.

Affected Versions and Available Updates

Additional image about Risks of Unrestricted File Uploads in WordPress

The vulnerability affects multiple versions of WordPress. Below are some of the affected versions and their corresponding updates that fix the issue:

  • WordPress 7.0 prior to 7.0.4
  • WordPress 6.9 prior to 6.9.7
  • WordPress 6.8 prior to 6.8.8
  • WordPress 6.7 prior to 6.7.7
  • WordPress 6.6 prior to 6.6.7
  • WordPress 6.5 prior to 6.5.10
  • WordPress 6.4 prior to 6.4.10
  • WordPress 6.3 prior to 6.3.10
  • WordPress 6.2 prior to 6.2.11
  • WordPress 6.1 prior to 6.1.12
  • WordPress 6.0 prior to 6.0.14
  • WordPress 5.9 prior to 5.9.16
  • WordPress 5.8 prior to 5.8.15
  • WordPress 5.7 prior to 5.7.17
  • WordPress 5.6 prior to 5.6.19
  • WordPress 5.5 prior to 5.5.20
  • WordPress 5.4 prior to 5.4.21
  • WordPress 5.3 prior to 5.3.23
  • WordPress 5.2 prior to 5.2.26
  • WordPress 5.1 prior to 5.1.24
  • WordPress 5.0 prior to 5.0.27
  • WordPress 4.9 prior to 4.9.31
  • WordPress 4.8 prior to 4.8.30
  • WordPress 4.7 prior to 4.7.35

For each affected version, WordPress has released an update that addresses this vulnerability.

Alert and Assessment from INCIBE

The National Cybersecurity Institute (INCIBE) has issued an early warning about this vulnerability, classifying it as high importance. INCIBE warns that exploitation could allow for remote code execution on affected sites.

The INCIBE alert highlights the relevance of WordPress file uploads without restrictions as an attack vector and the need to apply the published updates.

Limitations of Available Information

The official information does not detail confirmed attacks or the frequency of exploitation. No additional technical data is provided beyond the mechanism for uploading malicious Postscript files.

Therefore, it is not possible to establish the extent of the actual impact in specific environments or the existence of active exploits based on this vulnerability.

This alert is based on information published by INCIBE regarding unrestricted file uploads in WordPress.

Reviewed by
Published: 14/08/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.