The iPhone photo problem: a critical flaw in the software behind your uploads
Published · Disclosed September 18, 2026 · Reviewed by Adam Taylor
Most WordPress security news is about plugins. This one isn’t, which is exactly why it’s worth your attention: no amount of updating WordPress will fix it.
Wordfence found a critical flaw, scored 9.8 out of 10, in libheif: the software servers use to open HEIC images, the format iPhones save photos in. Versions 1.18.0 through 1.23.2 are affected, and it’s fixed in 1.23.3.
Why this affects your website
When someone uploads a photo straight from an iPhone, your server has to open that file to make thumbnails and resize it. It hands the file to libheif to do that. A photo built to exploit this flaw can make that software misbehave badly enough to run the attacker’s code on your server.
So the risky combination is: your site accepts image uploads, and your server can open HEIC files. That includes any site where people other than you upload images, such as a membership site, a classifieds site, a form that accepts photo attachments, or a shop where sellers add their own product pictures.
Wordfence noted the official WordPress Docker image was among the affected setups, which tells you how widely this software is installed without anyone thinking about it.
Am I affected?
This isn’t something you can check from your WordPress dashboard, because the software lives on the server underneath. Two ways to find out:
- Ask your hosting company whether their servers run libheif, and if so, whether they’ve updated to 1.23.3. Shared and managed hosts patch this centrally, and most will have done it or will do it shortly.
- If you run your own server or containers, check and update libheif yourself. If you build from the official WordPress Docker image, rebuild once an updated image is available.
What to do
- On shared or managed hosting: send your host a short message asking whether they’ve patched libheif. It’s a reasonable question and a good host will answer it plainly.
- On your own server: update the library, then restart the services that use it.
- Either way, be careful about who can upload files. Only let logged-in, trusted users upload images, and remove upload abilities from roles that don’t need them. That’s good practice regardless of this particular flaw.
There’s no sign this is being used against sites in the wild. We’re flagging it because it’s the kind of problem that sits outside what most site owners check, and because “keep WordPress updated” genuinely doesn’t help here.
Not sure what your host runs, or want us to ask on your behalf? Get in touch and we’ll sort it out.