Live  /  Incidents  /  Liquid Web

Liquid Web: Security Advisory: WordPress Security Update for CVE-2026-65640

Liquid Web · liquidweb.comImpact: noneResolved2026-08-12 15:44 UTC
Public — what happened

Summary

A security vulnerability, CVE-2026-65640, has been identified in WordPress that could allow an authenticated Author-level or higher user to achieve remote code execution through a malicious file upload on sites using Imagick and Ghostscript. The vulnerability has been addressed through updates across supported WordPress branches. Patched Versions: Customers should update to the following patched version for their respective WordPress branch: 7.0.4 6.9.7 6.8.8 6.7.7 6.6.7 6.5.10 6.4.10 6.3.10 6.2.11 6.1.12 6.0.14 5.9.16 5.8.15 5.7.17 5.6.19 5.5.20 5.4.21 5.3.23 5.2.26 5.1.24 5.0.27 4.9.31 4.8.30 4.7.35 Recommended Action: Customers are strongly encouraged to update WordPress core to the

Timeline

Source of record: provider status page. Mirrored as reported; times in UTC.

Independent path health

The status page is the symptom. SquidGrid measures the paths that reach Liquid Web against their own baselines — whether the routes carrying your traffic degraded, at which handoff, and who owns that stretch.

🔒 Sign in to see
Customers get the live Provider Assessment Report for Liquid Web: its full incident track record, what tends to break, and recent public reports of problems.

Included with any paid plan.

Open the Liquid Web report →

Related: Liquid Web status & history. SquidGrid is not affiliated with Liquid Web.