It was called .png and inside it was PostScript: the WordPress 7.0.4 flaw
On 12 August WordPress shipped 7.0.4 with a single fix: CVE-2026-65640, remote code execution by uploading a file that announces itself as an image and is PostScript inside. The patch reaches back to the 4.7 branch, from December 2016. For it to affect you two conditions have to hold at once, and the first one is not yours to decide. Why validating the extension does not validate what you think, what "requires Author role" really means, and how to check it in ten minutes.