Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2021-29447
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WordPress Authenticated XXE attack when installation is running PHP 8
Source: NVD (National Vulnerability Database)
Vulnerability Description
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Source: NVD (National Vulnerability Database)
Vulnerability Title
WordPress 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress是WordPress(Wordpress)基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。 WordPress 存在代码问题漏洞,攻击者可利用该漏洞在成功的XXE攻击中可以访问内部文件。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
WordPresswordpress-develop >= 5.6.0, < 5.7.1 -
II. Public POCs for CVE-2021-29447
#POC DescriptionSource LinkShenlong Link
1WordPress - Authenticated XXE (CVE-2021-29447)https://github.com/motikan2010/CVE-2021-29447POC Details
2WordPress XXE vulnerabilityhttps://github.com/Vulnmachines/wordpress_cve-2021-29447POC Details
3Wordpress XXE injection 구축 자동화 및 PoC https://github.com/dnr6419/CVE-2021-29447POC Details
4Nonehttps://github.com/AssassinUKG/CVE-2021-29447POC Details
5Nonehttps://github.com/b-abderrahmane/CVE-2021-29447-POCPOC Details
6Arbitrary file read controller based on CVE-2021-29447https://github.com/elf1337/blind-xxe-controller-CVE-2021-29447POC Details
7Proof of Concept for CVE-2021-29447 written in Pythonhttps://github.com/Val-Resh/CVE-2021-29447-POCPOC Details
8Exploit WordPress Media Library XML External Entity Injection (XXE) to exfiltrate files.https://github.com/M3l0nPan/wordpress-cve-2021-29447POC Details
9Nonehttps://github.com/mega8bit/exploit_cve-2021-29447POC Details
10A Golang program to automate the execution of CVE-2021-29447https://github.com/thomas-osgood/CVE-2021-29447POC Details
11Nonehttps://github.com/Abdulazizalsewedy/CVE-2021-29447POC Details
12Nonehttps://github.com/G01d3nW01f/CVE-2021-29447POC Details
13CVE-2021-29447 - Authenticated XXE Injection - WordPress < 5.7.1 & PHP > 8 https://github.com/viardant/CVE-2021-29447POC Details
14A proof of concept exploit for a wordpress 5.6 media library vulnerabilityhttps://github.com/0xRar/CVE-2021-29447-PoCPOC Details
15Nonehttps://github.com/andyhsu024/CVE-2021-29447POC Details
16Nonehttps://github.com/specializzazione-cyber-security/demo-CVE-2021-29447-lezionePOC Details
17PoC for CVE-2021-29447https://github.com/magicrc/CVE-2021-29447POC Details
18POC to exploit WordPress 5.6-5.7 (PHP 8+) Authenticated XXE Injection. https://github.com/Tea-On/CVE-2021-29447-Authenticated-XXE-WordPress-5.6-5.7POC Details
19The objective is to conduct a full-scale security assessment of a WordPress-based web application, culminating in a complete server compromise. The assessment will focus on exploiting a specific, real-world vulnerability (CVE-2021-29447) to achieve initial access.https://github.com/ArtemCyberLab/Project-Project-Chimera-Exploiting-a-Modern-WordPress-XXE-to-Pillage-Secrets-POC Details
20A XXE payload generator https://github.com/0xricksanchez/CVE-2021-29447POC Details
21This repo describes about cve-2021-29447 and a small script for exploiting automaticallyhttps://github.com/davids52/cve-2021-29447_auto-scriptPOC Details
22Nonehttps://github.com/rdana55/CVE-2021-29447-PoCPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2021-29447
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2021-29447

No comments yet


Leave a comment