WordPress and libheif: Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads

WordPress and libheif: Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads

Critical libheif Vulnerability Enables Remote Code Execution in WordPress

A severe heap-buffer-overflow flaw in libheif, tracked as GHSA-x8r2-mggj-j6wr, allows authenticated WordPress users to achieve remote code execution (RCE) by uploading a maliciously crafted HEIC image via the Media Library. The vulnerability affects the library’s uncompressed-image (unci) decoder and was patched in libheif 1.23.3.

How the Exploit Works

The flaw resides in libheif’s mixed-interleave YCbCr decoding path, where a malicious HEIC file can declare the Cb chroma component as 16-bit while the Cr component remains 8-bit. Despite allocating only one byte per sample for the Cr plane, the vulnerable code writes both chroma channels using the Cb’s two-byte width, leading to a file-controlled out-of-bounds write and heap corruption.

Researchers at Fortbridge demonstrated that this memory corruption can be chained into authenticated RCE in specific WordPress environments:

  • Ubuntu 26.04 (WordPress 7.1.1, PHP-FPM 8.5.4, ImageMagick 7.1.2.18, libheif 1.21.2)
  • Debian 13 (WordPress 7.0, PHP-FPM 8.4.24, ImageMagick 7.1.1.43, libheif 1.19.8)

In lab tests, the exploit succeeded in 6 of 8 Ubuntu runs and 22 of 24 Debian runs, executing commands as the www-data PHP-FPM account after an Author-level user uploaded the malicious HEIC file.

Exploit Chain & Requirements

The attack requires:

  • An authenticated WordPress user with upload_files capability (typically Author or higher).
  • PHP’s Imagick extension and ImageMagick processing the uploaded HEIC file, passing it to libheif for decoding.
  • No single malicious upload instead, the exploit first leaks memory addresses via WordPress-generated image derivatives (e.g., JPEG thumbnails), then crafts an ASLR-adjusted payload based on the target’s environment.

The memory disclosure relies on a separate libheif flaw (GHSA-2jg2-4ch7-h545), patched in libheif 1.23.2, which involves out-of-bounds reads/writes in derived-image handling.

Mitigation & Patching

  • Upgrade libheif to 1.23.3 or later (API/ABI-compatible with 1.23.2).
  • Debian released a security update (1.23.4-1~deb13u1) addressing multiple libheif vulnerabilities.
  • Restart PHP-FPM after patching to clear vulnerable library instances from memory.
  • Disable HEIC/AVIF uploads if not required.
  • Isolate image processing in a least-privileged service with restricted access.
  • Monitor for PHP-FPM worker crashes or HTTP 503 errors during image uploads, which may indicate exploitation attempts.

The vulnerability highlights how native-code dependencies in image-processing stacks can expose web applications to unexpected attack surfaces, even in hardened WordPress environments.

Source: https://gbhackers.com/libheif-vulnerability/

FORTBRIDGE cybersecurity rating report: https://www.rankiteo.com/company/fortbridge

WordPress cybersecurity rating report: https://www.rankiteo.com/company/wordpress

"id": "FORWOR1791210523",
"linkid": "fortbridge, wordpress",
"type": "Vulnerability",
"date": "5/2025",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'industry': 'Web Development/Technology',
                        'location': 'Global',
                        'name': 'WordPress',
                        'type': 'Content Management System (CMS)'},
                       {'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Ubuntu 26.04',
                        'type': 'Operating System'},
                       {'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Debian 13',
                        'type': 'Operating System'}],
 'attack_vector': 'Malicious file upload (HEIC image)',
 'data_breach': {'file_types_exposed': ['HEIC']},
 'description': 'A severe heap-buffer-overflow flaw in libheif '
                '(GHSA-x8r2-mggj-j6wr) allows authenticated WordPress users to '
                'achieve remote code execution (RCE) by uploading a '
                'maliciously crafted HEIC image via the Media Library. The '
                'vulnerability affects the library’s uncompressed-image (unci) '
                'decoder and was patched in libheif 1.23.3.',
 'impact': {'operational_impact': 'Potential unauthorized code execution as '
                                  'www-data user',
            'systems_affected': 'WordPress environments with PHP-FPM, '
                                'ImageMagick, and libheif'},
 'lessons_learned': 'Native-code dependencies in image-processing stacks can '
                    'expose web applications to unexpected attack surfaces, '
                    'even in hardened WordPress environments.',
 'post_incident_analysis': {'corrective_actions': ['Patch libheif to version '
                                                   '1.23.3 or later',
                                                   'Address memory disclosure '
                                                   'flaw (GHSA-2jg2-4ch7-h545) '
                                                   'in derived-image handling'],
                            'root_causes': 'Heap-buffer-overflow in libheif’s '
                                           'mixed-interleave YCbCr decoding '
                                           'path due to inconsistent chroma '
                                           'component bit-depth handling'},
 'recommendations': ['Upgrade libheif to 1.23.3 or later',
                     'Restart PHP-FPM after patching',
                     'Disable HEIC/AVIF uploads if not required',
                     'Isolate image processing in a least-privileged service',
                     'Monitor for PHP-FPM worker crashes or HTTP 503 errors '
                     'during image uploads'],
 'references': [{'source': 'Fortbridge Research'},
                {'source': 'GitHub Advisory (GHSA-x8r2-mggj-j6wr)'},
                {'source': 'Debian Security Update (1.23.4-1~deb13u1)'}],
 'response': {'containment_measures': ['Upgrade libheif to 1.23.3 or later',
                                       'Restart PHP-FPM after patching',
                                       'Disable HEIC/AVIF uploads if not '
                                       'required',
                                       'Isolate image processing in a '
                                       'least-privileged service'],
              'enhanced_monitoring': 'Monitor for PHP-FPM worker crashes or '
                                     'HTTP 503 errors',
              'remediation_measures': ['Apply Debian security update '
                                       '(1.23.4-1~deb13u1)',
                                       'Monitor for PHP-FPM worker crashes or '
                                       'HTTP 503 errors during image uploads']},
 'title': 'Critical libheif Vulnerability Enables Remote Code Execution in '
          'WordPress',
 'type': 'Remote Code Execution (RCE)',
 'vulnerability_exploited': 'Heap-buffer-overflow in libheif’s '
                            'mixed-interleave YCbCr decoding path '
                            '(GHSA-x8r2-mggj-j6wr)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.