Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
Researchers have demonstrated an attack chain in which a malicious HEIC image uploaded to a WordPress Media Library can lead to remote code execution in the PHP-FPM process. The risk comes from libheif, a widely used component for reading HEIC, HEIF, and AVIF formats.