CVE-2021-29447

WordPress Authenticated XXE attack when installation is running PHP 8

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.


We have discovered 76,977 live websites that are affected by CVE-2021-29447.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains76,977 live websites (0.89% of WordPress install base)
Vulnerable Versions
  • from 5.6 through 5.7.1
Vulnerable Versions Count18 versions ( 2.71% of all versions)


Common Weakness Enumeration

CWE-611 Improper Restriction of XML External Entity Reference



Details

  • Published - Apr 16, 2021
  • Updated - Aug 3, 2024

Website Distribution by Country

Number of websites using CVE-2021-29447
United States14,368 websites



Germany10,025 websites
Japan7,960 websites
Italy4,081 websites
France4,032 websites
Russia3,621 websites
Poland3,128 websites
GB2,621 websites
Netherlands2,450 websites
Spain2,323 websites

Website Distribution by TLD

Number of websites using CVE-2021-29447
.com28,879 websites
.de6,186 websites
.ru2,935 websites
.org2,687 websites
.it2,600 websites
.pl2,371 websites
.net2,224 websites
.nl2,139 websites
.jp1,724 websites
.fr1,533 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-29447

Top websites that are affected by CVE-2021-29447. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*******.co Serbia**,***
*****************.org United States**,***
*****.tv **,***
*********.***.au United States**,***
******************.com United States**,***
*****.*******.org United States**,***
***********.com United States**,***
******.*******.org United States**,***
***.edu United States**,***
*********.net United States**,***
See full domain list

FAQ

CVE-2021-29447 is Improper Restriction of XML External Entity Reference in WordPress
A total of 76,977 websites have been identified as vulnerable to CVE-2021-29447, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2021-29447 vulnerability.
WordPress versions up to 5.7.1 are vulnerable to CVE-2021-29447.
CVE-2021-29447 is resolved in version 5.7.1 of WordPress.