On 12 August 2026, WordPress released version 7.0.4 as a security release. If you run a self-managed WordPress site on a Hostify VPS or dedicated server, please update as soon as possible.
What Was Fixed
The release fixes a remote code execution vulnerability (CVE-2026-65640 / GHSA-8vr3-7mxf-gx8w) that could be triggered by a malicious file upload from an authenticated Author-level user account. Exploitation requires sites running with Imagick and Ghostscript enabled for image handling, but the fix is being applied everywhere regardless.
As a courtesy, WordPress is backporting the fix to all supported branches back to 4.7, so older installations will also receive a patched release as those backports ship.
What Hostify Did
- All Hostify-managed WordPress installations on shared and WordPress hosting plans are being updated to 7.0.4 automatically.
- Server-level security rules remain in place to detect and block exploitation attempts.
What You Should Do
If you self-manage WordPress on a Hostify VPS or dedicated server, update to 7.0.4 now. Log into your dashboard, go to Dashboard > Updates, and click Update Now. You can also check that automatic background updates are enabled. Remember, only the most recent WordPress version is actively supported — staying current is your best protection.
As always, our support team is available 24/7. Open a ticket if you need help updating or verifying your site.