>_
Delvok
← Back to Blog
Vulnerability Alert

Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server

September 30, 2026·Delvok Threat Intel·2 min read

A high-severity security advisory was published regarding WordPress.

Executive Threat Summary

Wordfence Argus found a critical CVSS 9.8 vulnerability in libheif, a library many servers use to process HEIC images. We demonstrated protected-file disclosure and code execution on one exact WordPress deployment. Exploitation is target-specific, but HEIF Heist shows that adapting image exploits to real systems is practical.
The post Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server appeared first on Wordfence.

This security vulnerability presents a direct risk of unauthorized data access, arbitrary script injection, or remote site compromise if left unaddressed. Because threat actors scan the internet automatically within hours of vulnerability disclosures, affected sites must be audited immediately.

Action Plan for Website Owners

  1. Check Your Installed Version: Verify what version of WordPress is running in your WordPress admin dashboard (Plugins → Installed Plugins).
  2. Apply Patches Immediately: If a newer release is available, backup your database and update the software without delay.
  3. Inspect for Indicators of Attack: If your site cannot be updated immediately, check for unexpected administrative accounts or unusual traffic spikes.
  4. Get an Infrastructure Audit: Submit a rescue or security inquiry with Delvok. We verify server integrity and migrate your site to an isolated container environment.

What Delvok Does Differently

Every site we rescue is migrated to isolated container infrastructure — your own web root, database, and server process. 24/7 monitoring catches threats before they become problems. Forensic-grade remediation ensures nothing is left behind.

Get Protected