At this rate, WordPress is releasing security updates faster than plugin authors can change their “Tested up to” header.
Only six days after WordPress 7.0.3, version 7.0.4 was released on August 12, 2026. This is another security release, so site owners are advised to update immediately.
The release fixes an authenticated Author+ remote code execution vulnerability involving malicious file uploads on sites using Imagick and Ghostscript. The vulnerability was responsibly reported by the team at pwn.ai.
Although exploitation requires an authenticated account with Author-level access or higher, remote code execution is serious. Multi-author websites, membership platforms, marketplaces and sites allowing user-submitted content should update without delay.
The fix modifies only one WordPress core file:
/wp-includes/class-wp-image-editor-imagick.php
The security fix was also backported to affected WordPress branches from 6.9 down to 4.7. WordPress 4.6 and earlier no longer receive security updates.
You can update from Dashboard → Updates or download the appropriate release from WordPress.org.
After updating, clear your caches and verify that image uploads and thumbnail generation still work correctly. If automatic core updates are enabled, check that the update was actually installed.
Hopefully WordPress 7.0.5 waits until I finish writing this forum topic about 7.0.4. ![]()