Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek.

WordPress has released version 7.0.4, which includes a patch for a remote code execution (RCE) vulnerability. The flaw reportedly allowed attackers with Author-level user permissions or higher to execute arbitrary code on affected systems. The vulnerability was exploitable through the use of malicious Postscript files.
The core mechanism of this vulnerability appears to stem from how WordPress, or a component it utilizes, processes Postscript files. Postscript is a page description language that, while powerful for document rendering, can also be misused if its interpreter is not securely sandboxed or if it allows the execution of arbitrary commands. In this specific case, an attacker with the requisite permissions could upload or manipulate a file containing malicious Postscript code, which would then be processed by the server, leading to code execution.
The critical aspect of this flaw is the required permission level. An attacker would need at least Author-level access to a WordPress site. This means the vulnerability is not a zero-click or unauthenticated attack. Instead, it targets sites where an attacker has already gained a foothold, perhaps through compromised credentials, or where a malicious insider with Author privileges exists. This significantly narrows the immediate threat landscape compared to publicly accessible vulnerabilities but still poses a serious risk to compromised or mismanaged sites.
Products in the content management system (CMS) category, especially those that allow users to upload and process various file types, commonly face challenges in securely handling potentially dangerous file formats. Image processing libraries, document parsers, and media handlers are frequent targets for such vulnerabilities. Ensuring that all uploaded content is thoroughly validated, sanitized, and processed within secure, isolated environments is a continuous security challenge for vendors.
Mitigation for this class of issue typically involves several layers of defense. Beyond patching to the latest version (WordPress 7.0.4 in this instance), administrators should enforce strong password policies and multi-factor authentication for all user accounts, especially those with elevated privileges. Regularly auditing user accounts and their assigned roles can help identify and revoke unnecessary permissions. Additionally, server-level security measures, such as disabling unnecessary interpreters or ensuring that file uploads are stored outside the web root and scanned for malicious content, can provide further protection.
The discovery and patching of this RCE vulnerability in WordPress underscore the ongoing security challenges inherent in widely adopted software platforms. Even with robust development practices, the complexity of modern web applications, coupled with the need to support diverse functionalities like file uploads, creates potential attack surfaces. Regular updates, vigilant monitoring, and adherence to security best practices remain crucial for maintaining the integrity and security of web properties.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]