TL;DR
Fortbridge researcher Adrian Tiron has published a working proof-of-concept for a WordPress libheif RCE chain. It turns an authenticated HEIC image upload into code execution as the web server account. Both the technical details and the exploit code are now public, so unpatched sites that decode HEIC or AVIF uploads should update libheif at once.
See a WordPress CVE's exploit risk spike before it becomes a headline.
Get EPSS spike alertsWhy It Matters
WordPress runs a large share of the web, and many installs accept image uploads. This WordPress libheif RCE does not target WordPress code itself. Instead, it reaches libheif, the native library that ImageMagick uses to decode HEIC and AVIF files. A bug in that layer sits behind countless web apps.
The attack needs only an authenticated account with the upload_files capability. In a standard install, Tiron notes, “that normally means Author or higher.” A plugin that allows guest image uploads could lower that bar, though the researchers did not test that case.
Crucially, the write-up and the code are both out in the open. The full analysis appears in the Fortbridge research report, and the exploit lives in a public GitHub proof-of-concept repository. That public disclosure raises the urgency for defenders.
How the Attack Works
The chain combines two libheif vulnerability families. Neither requires a flaw in WordPress itself.
A File-Controlled Heap Overflow
The core bug is GHSA-x8r2-mggj-j6wr, in libheif’s uncompressed image decoder. A crafted file can declare mismatched widths for two chroma channels. As a result, a write loop runs past its buffer. Per the advisory, “each Cr write therefore advances too far, eventually carrying file-controlled bytes beyond the Cr allocation.” That memory corruption is what the chain builds on.
A Leak Through Returned Images
Modern systems randomize memory with ASLR, so an attacker must first learn where libraries sit. Here the second family, GHSA-2jg2-4ch7-h545, helps. Crafted images over-read heap memory, and WordPress returns that data inside the resized image derivatives it generates. The exploit reads addresses back out of those pixels. Tiron calls this a “remotely calibrated path,” since it recovers live addresses over HTTP rather than assuming them.
From Overflow to Command Execution
With addresses in hand, the overflow is steered to hijack a C++ virtual call during decoder teardown. The decode then runs a command as the PHP-FPM account. The team confirmed success only when a separate request proved the command ran, not merely when a worker crashed. As the report puts it, “a 503 alone is crash telemetry, never RCE proof.”
Exploitation Status
A public proof-of-concept now exists, which the Fortbridge repository confirms. However, the researchers report no exploitation in the wild. The exploit is also narrow. It works only against two exact software stacks that Fortbridge measured in the lab, on Ubuntu 26.04 and Debian 13. Tiron is blunt about the limits: the results “are not universal success rates for WordPress or libheif.”
Even so, the public details lower the bar for others to adapt the technique. Treat this as a serious risk, not a lab curiosity.
Affected Versions
The flaws sit in libheif, not WordPress core. According to Fortbridge:
- GHSA-x8r2-mggj-j6wr affects libheif 1.18.0 through 1.23.2, fixed in 1.23.3.
- GHSA-2jg2-4ch7-h545 is fixed in 1.23.2.
The lab stacks paired these with ImageMagick 7.1.x, PHP-FPM and glibc on amd64. Any site whose image pipeline loads a vulnerable libheif build is a candidate, regardless of the WordPress version on top.
Patch and Mitigation Steps
Fortbridge lists several defenses. Patching comes first.
- Update libheif to 1.23.3 or later. Use your distribution’s current security package, and check which library the image stack actually loads.
- Shrink the attack surface. If HEIC and AVIF uploads are not needed, reject them before native decoding.
- Isolate image processing. Decode untrusted media in a disposable, least-privileged service with restricted network access and no application secrets.
- Treat native crashes as security events. Correlate repeated PHP-FPM child exits and 503 responses with uploads that use unusual image relationships.
- Constrain impact. Block script execution from upload directories to limit what an attacker can do after a successful write.
None of the later steps replace the patch. Since the WordPress libheif RCE details and code are public, updating the library is the one durable fix.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!