Malicious HEIC Images Enable Remote Code Execution on WordPress Servers
A vulnerability in the libheif library allows attackers to achieve remote code execution on WordPress servers by uploading specially crafted HEIC image files.

Researchers have uncovered a critical vulnerability within the libheif library that can be exploited to achieve remote code execution (RCE) on WordPress servers. The attack chain leverages the processing of HEIC image files, a format commonly used by modern smartphones, to corrupt memory within the ImageMagick processing service. This corruption, when combined with memory disclosure techniques, can lead to the execution of arbitrary code as the PHP-FPM user.
The primary vulnerability, tracked as GHSA-x8r2-mggj-j6wr, resides in libheif's uncompressed image decoder. Attackers can craft a malicious HEIC file that declares color channels with differing byte widths. The decoder, when processing this malformed input, allocates insufficient memory for one channel but proceeds to write data using the larger declared width. This results in an out-of-bounds write, allowing attacker-controlled data to overwrite adjacent memory regions.
Exploiting this vulnerability in a repeatable manner is complex due to modern system memory randomization. The researchers developed a two-stage process: first, they upload specially crafted disclosure images. Subsequently, they analyze the pixels within the JPEG derivatives generated by WordPress. This analysis reveals sufficient memory information to identify the specific running library build, enabling the tailoring of a final exploit payload.
The successful exploitation chain requires an authenticated user with upload_files permissions, typically an Author role or higher in WordPress. The researchers demonstrated repeatable code execution on specific Linux software stacks, including Ubuntu 26.04 with specific versions of WordPress, PHP-FPM, ImageMagick, and libheif, as well as Debian 13 with a similar configuration. The exploit targets the decoder's virtual function table during its cleanup routine, redirecting execution flow to attacker-controlled code.
Fortbridge researchers identified the core overflow, while Alex Thomas and Wordfence contributed to discovering the exploit chain. The successful exploitation was validated on two distinct Linux environments, highlighting the dependency on precise software versions and configurations. While not indicative of a widespread active campaign, the findings underscore the risks associated with processing untrusted media files, especially when utilizing native libraries.
To mitigate this threat, administrators are strongly advised to update libheif to version 1.23.3 or later, which addresses GHSA-x8r2-mggj-j6wr. A related disclosure issue, GHSA-2jg2-4ch7-h545, is fixed in libheif 1.23.2. Beyond updating the library, security teams should ensure distribution security updates are applied and verify that the correct libheif version is loaded by the image processing stack.
Further protective measures include blocking HEIC and AVIF uploads if they are not required by the site. For environments that must process these file types, consider removing the uncompressed codec from custom libheif builds, processing untrusted media in isolated, low-privilege services, restricting outbound network access, and keeping application secrets separate from image processing workers. Monitoring for repeated PHP-FPM worker crashes or HTTP 503 errors following HEIC uploads can also serve as indicators of potential compromise.
While the report did not identify an active exploitation campaign in the wild, the vulnerability presents a significant risk to WordPress sites utilizing specific configurations. The researchers provided indicators of compromise, including a specific file name used in their validation chain, to aid in detection efforts.