CVE-2021-29447

WordPress Authenticated XXE attack when installation is running PHP 8

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.


We have discovered 100,858 live websites that are affected by CVE-2021-29447.

Test my site




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains100,858 live websites (1.09% of WordPress install base)
Vulnerable Versions
  • from 5.6 before 5.7.1
Vulnerable Versions Count18 versions ( 1.93% of all versions)


Common Weakness Enumeration

CWE-611 Improper Restriction of XML External Entity Reference



Details

  • Published - Apr 16, 2021
  • Updated - Aug 3, 2024

CVE-2021-29447 usage by Country

United States24,494 websites



Germany14,757 websites
Japan9,114 websites
France6,211 websites
Russia4,485 websites
Poland4,084 websites
Netherlands3,120 websites
GB2,985 websites
Spain2,647 websites
Italy2,384 websites

CVE-2021-29447 usage by TLD

.com38,037 websites
.de8,013 websites
.ru3,891 websites
.org3,547 websites
.pl3,401 websites
.nl2,936 websites
.net2,877 websites
.co.uk2,028 websites
.fr2,024 websites
.jp2,017 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-29447

Top websites that are affected by CVE-2021-29447. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States*,***
**********.com France*,***
**************.com United States**,***
*********.com United States**,***
***********.ru Russia**,***
*******.co Germany**,***
*****************.org Germany**,***
*****.tv Japan**,***
*****.***.**.uk United States**,***
*********.***.au United States**,***
See full domain list

FAQ

CVE-2021-29447 is Improper Restriction of XML External Entity Reference in WordPress
A total of 100,858 websites have been identified as vulnerable to CVE-2021-29447, discovered through global website indexing conducted by WebTechSurvey.
WordPress is susceptible to CVE-2021-29447 vulnerability.
WordPress versions before 5.7.1 are vulnerable to CVE-2021-29447.
Version 5.7.1 of WordPress addresses the CVE-2021-29447 security vulnerability.