A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE

On a clean WordPress installation with no plugins, a researcher uploaded a crafted photo through the Media Library, copied /etc/passwd to a public folder and left a working PHP file on the server. The flaw is not in WordPress. It sits several layers down, in libheif, the library that much of the Linux ecosystem uses to open the … Continue reading A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE