A malicious HEIC image can exploit libheif through WordPress uploads, enabling remote code execution on vulnerable servers.