WordPress + libheif (Fortbridge, 5 Oct): crafted HEIC upload by an Author-level user → code execution as PHP-FPM via ImageMagick — libheif GHSA-x8r2-mggj-j6wr (CVSS 9.8); patch libheif 1.23.3
Fortbridge published a working exploit chain on 5 October 2026 that turns an ordinary WordPress Media Library upload into code execution on the web server. WordPress hands uploaded HEIC images to ImageMagick, which decodes them with libheif. The chain first uses the derived-item and pixel-plane out-of-bounds read in libheif advisory GHSA-2jg2-4ch7-h545 (fixed in 1.23.2) to leak library and heap addresses through the JPEG thumbnails WordPress generates, then triggers the heap overflow in GHSA-x8r2-mggj-j6wr, a flaw in libheif's uncompressed (unci) decoder when the two chroma channels declare different bit depths, to hijack a C++ virtual call and run commands as the www-data PHP-FPM account. It needs a logged-in user with the upload_files capability (Author or higher by default); Fortbridge did not test guest uploads and validated it only on two exact Ubuntu and Debian stacks (6 of 8 and 22 of 24 runs succeeded). The libheif advisory, credited to Alex Thomas of Wordfence working with an agentic AI assessment framework, rates the overflow Critical (CVSS 3.1 9.8) and has no CVE yet. This is lab research, not an observed campaign. Wire: Cyber Security News 5 Oct.
- Product
- libheif (HEIC/HEIF/AVIF decoder) as used by ImageMagick in WordPress server-side image processing
- Versions
- GHSA-x8r2-mggj-j6wr: libheif >= 1.18.0 and <= 1.23.2, fixed 1.23.3. GHSA-2jg2-4ch7-h545: libheif <= 1.23.1, fixed 1.23.2. Exploit validated on one Ubuntu and one Debian WordPress/PHP-FPM/ImageMagick build.
- CVSS
- (CVSS 3.1, libheif GHSA; no CVE assigned)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Update libheif to 1.23.3 or later (or your distribution's patched package) on any host where ImageMagick or another image library decodes user uploads, then restart PHP-FPM. If you cannot patch yet, disable HEIC/HEIF decoding in the ImageMagick policy, review which WordPress accounts hold upload_files, and check plugins that let guests upload images.
Primary: Fortbridge — WordPress libheif RCE research (5 Oct 2026) · Vendor: libheif GHSA-x8r2-mggj-j6wr — unci mixed-interleave heap overflow (published 1 Sep 2026; fixed 1.23.3) · Cyber Security News — Malicious HEIC images can trigger remote code execution on WordPress servers (5 Oct 2026)
