securityonline.info 6 Oct 2026, 07:01 UTC

WordPress HEIC Upload Flaw Enables Code Execution in a Lab Exploit

WordPress HEIC Upload Flaw Enables Code Execution in a Lab Exploit

FORTBRIDGE researcher Adrian Tiron has published a working proof-of-concept for a WordPress libheif remote code execution (RCE) chain, turning an authenticated HEIC image upload into code execution under the web server account. The chain relies on two libheif vulnerability families rather than WordPress itself. First, a file-controlled heap overflow in libheif’s uncompressed image decoder (GHSA-x8r2-mggj-j6wr) can cause memory corruption by mismatched chroma channel widths.

Second, a leak through returned images (GHSA-2jg2-4ch7-h545) enables over-read of heap memory, with WordPress returning data inside derived images, allowing the attacker to recover live addresses over HTTP. With addresses in hand, the overflow is steered to hijack a C++ virtual call during decoder teardown, yielding command execution as the PHP-FPM account. The researchers confirmed success via an additional request showing the command ran, not merely via worker crashes.

The flaws sit in libheif, not WordPress core, and the public PoC exists in the Fortbridge repository, with the exploit hosted on GitHub. In practice, the attack requires an authenticated account with upload_files capability and has been demonstrated on a narrow set of lab stacks—Ubuntu 26.04 and Debian 13—so it is not claimed to be universally applicable to all WordPress or libheif deployments.

Affected versions are libheif 1.18.0 through 1.23.2 (fixed in 1.23.3) for GHSA-x8r2-mggj-j6wr, and GHSA-2jg2-4ch7-h545 is fixed in 1.23.2. Fortbridge recommends patching and reducing exposure, including updating to libheif 1.23.3 or later, gating HEIC/AVIF uploads, isolating image processing, and monitoring for unusual crashes.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline