← back
CVE-2021-29447highCWE-611

WordPress Authenticated XXE attack when installation is running PHP 8

65Vexday Risk Score

Keep watching. It has a public proof of concept.

ssvc Attendcvss 7.1epss 86%
from disclosure to weapon1 days
Published on NVDApr 15
1st PoC+1d
exploitation probability
86%top 1% of all CVEs
observed exploitation
nono source reports it
26 public exploit(s)
In short

WordPress users with file upload permissions (like Authors) can exploit an XML parsing flaw in the Media Library to read internal server files, but only if the site runs PHP 8. This vulnerability has been patched in WordPress 5.7.1 and older versions.

Technical detail

An authenticated XXE (XML External Entity) vulnerability exists in WordPress Media Library when running on PHP 8, allowing users with upload capabilities to parse malicious XML files and access sensitive internal files through entity expansion. The attack requires file upload permissions and PHP 8 environment; patched in WordPress 5.7.1+.

Summary generated and translated by AI from the official description.
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
public PoCs found26
exploitdbwww.exploit-db.com/exploits/50304unverifiedgithubgithub.com/motikan2010/CVE-2021-2944743githubgithub.com/mega8bit/exploit_cve-2021-294477githubgithub.com/0xRar/CVE-2021-29447-PoC6githubgithub.com/M3l0nPan/wordpress-cve-2021-294474githubgithub.com/Vulnmachines/wordpress_cve-2021-294474githubgithub.com/dnr6419/CVE-2021-294473githubgithub.com/elf1337/blind-xxe-controller-CVE-2021-294473githubgithub.com/thomas-osgood/CVE-2021-294473githubgithub.com/Tea-On/CVE-2021-29447-Authenticated-XXE-WordPress-5.6-5.72githubgithub.com/Abdulazizalsewedy/CVE-2021-294472githubgithub.com/b-abderrahmane/CVE-2021-29447-POC1githubgithub.com/ArtemCyberLab/Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-1githubgithub.com/Val-Resh/CVE-2021-29447-POC1githubgithub.com/viardant/CVE-2021-294470githubgithub.com/AssassinUKG/CVE-2021-294470githubgithub.com/G01d3nW01f/CVE-2021-294470githubgithub.com/magicrc/CVE-2021-294470githubgithub.com/andyhsu024/CVE-2021-294470githubgithub.com/specializzazione-cyber-security/demo-CVE-2021-29447-lezione0githubgithub.com/rdana55/CVE-2021-29447-PoC0githubgithub.com/danilo1992-sys/CVE-2021-294470githubgithub.com/0xricksanchez/CVE-2021-294470githubgithub.com/davids52/cve-2021-29447_auto-script0cve_referencepacketstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.htmlunverifiedcve_referencepacketstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.htmlunverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.