When a PNG Isn’t a PNG: WordPress Patches an Author-Level Imagick RCE
WordPress 7.0.4 patches an author-level RCE in how uploaded media is handed to ImageMagick.
WordPress maintenance release 7.0.4 includes a security fix that changes how uploaded media is passed to ImageMagick, closing a path that let a logged-in author turn a crafted image upload into remote code execution. Patchstack's analysis explains the flaw as a file-type handling issue where a PNG may not be treated as a PNG. The text does not mention a CVE ID or observed exploitation, but the flaw affects extremely widely deployed software.