From the release notes: “An authenticated Author+ remote code execution issue via malicious file upload on sites that use Imagick and Ghostscript reported by the team at pwn.ai”

WordPress 7.0.4 Security Release
Core Team @ wordpress.org • 2 weeks ago






