Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.
We have discovered 100,858 live websites that are affected by CVE-2021-29447.
Product | |
Category | Content Management System |
Vulnerable Domains | 100,858 live websites (1.09% of WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 18 versions ( 1.93% of all versions) |
![]() | 24,494 websites |
![]() | 14,757 websites |
![]() | 9,114 websites |
![]() | 6,211 websites |
![]() | 4,485 websites |
![]() | 4,084 websites |
![]() | 3,120 websites |
![]() | 2,985 websites |
![]() | 2,647 websites |
![]() | 2,384 websites |
.com | 38,037 websites |
.de | 8,013 websites |
.ru | 3,891 websites |
.org | 3,547 websites |
.pl | 3,401 websites |
.nl | 2,936 websites |
.net | 2,877 websites |
.co.uk | 2,028 websites |
.fr | 2,024 websites |
.jp | 2,017 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
***********.com | ![]() | *,*** | |
**********.com | ![]() | *,*** | |
**************.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
***********.ru | ![]() | **,*** | |
*******.co | ![]() | **,*** | |
*****************.org | ![]() | **,*** | |
*****.tv | ![]() | **,*** | |
*****.***.**.uk | ![]() | **,*** | |
*********.***.au | ![]() | **,*** |
FAQ