Author: revibe

August Was a Patch Month. The Hard Part Is Updating the Fleet.

August 2026 was busy on the core side. WordPress 7.0.3 landed on 6 August with a pre-auth login-screen XSS (CVE-2026-64638) that can chain to PHP execution, plus a pile of contributor-level XSS fixes. WordPress 7.0.4 followed on 12 August for an author-level remote code execution path through a malicious Postscript upload when Imagick and Ghostscript […]

Read More