{"api_version":"1","generated_at":"2026-07-24T23:37:59+00:00","cve":"CVE-2021-29447","urls":{"html":"https://cve.report/CVE-2021-29447","api":"https://cve.report/api/cve/CVE-2021-29447.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-29447","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-29447"},"summary":{"title":"CVE-2021-29447","description":"Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.","state":"PUBLIC","assigner":"security-advisories@github.com","published_at":"2021-04-15 21:15:00","updated_at":"2022-10-27 23:06:00"},"problem_types":["CWE-611"],"metrics":[],"references":[{"url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00017.html","name":"[debian-lts-announce] 20210421 [SECURITY] [DLA 2630-1] wordpress security update","refsource":"MLIST","tags":[],"title":"[SECURITY] [DLA 2630-1] wordpress security update","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.debian.org/security/2021/dsa-4896","name":"DSA-4896","refsource":"DEBIAN","tags":[],"title":"Debian -- Security Information -- DSA-4896-1 wordpress","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://wordpress.org/news/category/security/","name":"https://wordpress.org/news/category/security/","refsource":"MISC","tags":[],"title":"News – Security – WordPress.org","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.sonarsource.com/wordpress-xxe-security-vulnerability/","name":"https://blog.sonarsource.com/wordpress-xxe-security-vulnerability/","refsource":"MISC","tags":[],"title":"WordPress 5.7 XXE Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rv47-pc52-qrhh","name":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rv47-pc52-qrhh","refsource":"CONFIRM","tags":[],"title":"WordPress: Authenticated XXE attack when installation is running PHP 8 · Advisory · WordPress/wordpress-develop · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://packetstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.html","name":"http://packetstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.html","refsource":"MISC","tags":[],"title":"WordPress 5.7 Media Library XML Injection ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://packetstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.html","name":"http://packetstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.html","refsource":"MISC","tags":[],"title":"XML External Entity Via MP3 File Upload On WordPress ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-29447","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-29447","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"29447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"10.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"29447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"debian","cpe5":"debian_linux","cpe6":"9.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"29447","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wordpress","cpe5":"wordpress","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2021-29447","qid":"154095","title":"WordPress XXE Attack due to XML Parsing Issue in Media Library"},{"cve":"CVE-2021-29447","qid":"178554","title":"Debian Security Update for wordpress (DLA 2630-1)"},{"cve":"CVE-2021-29447","qid":"178560","title":"Debian Security Update for wordpress (DSA 4896-1)"},{"cve":"CVE-2021-29447","qid":"180298","title":"Debian Security Update for wordpress (CVE-2021-29447)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security-advisories@github.com","ID":"CVE-2021-29447","STATE":"PUBLIC","TITLE":"WordPress Authenticated XXE attack when installation is running PHP 8"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"wordpress-develop","version":{"version_data":[{"version_value":">= 5.6.0, < 5.7.1"}]}}]},"vendor_name":"WordPress"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled."}]},"impact":{"cvss":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","version":"3.1"}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"{\"CWE-611\":\"Improper Restriction of XML External Entity Reference\"}"}]}]},"references":{"reference_data":[{"name":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rv47-pc52-qrhh","refsource":"CONFIRM","url":"https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-rv47-pc52-qrhh"},{"name":"https://wordpress.org/news/category/security/","refsource":"MISC","url":"https://wordpress.org/news/category/security/"},{"refsource":"MLIST","name":"[debian-lts-announce] 20210421 [SECURITY] [DLA 2630-1] wordpress security update","url":"https://lists.debian.org/debian-lts-announce/2021/04/msg00017.html"},{"refsource":"DEBIAN","name":"DSA-4896","url":"https://www.debian.org/security/2021/dsa-4896"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.html","url":"http://packetstormsecurity.com/files/163148/XML-External-Entity-Via-MP3-File-Upload-On-WordPress.html"},{"refsource":"MISC","name":"http://packetstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.html","url":"http://packetstormsecurity.com/files/164198/WordPress-5.7-Media-Library-XML-Injection.html"},{"refsource":"MISC","name":"https://blog.sonarsource.com/wordpress-xxe-security-vulnerability/","url":"https://blog.sonarsource.com/wordpress-xxe-security-vulnerability/"}]},"source":{"advisory":"GHSA-rv47-pc52-qrhh","discovery":"UNKNOWN"}},"nvd":{"publishedDate":"2021-04-15 21:15:00","lastModifiedDate":"2022-10-27 23:06:00","problem_types":["CWE-611"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":6.5,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*","versionStartIncluding":"5.6.0","versionEndExcluding":"5.7.1","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"29447","Ordinal":"204651","Title":"CVE-2021-29447","CVE":"CVE-2021-29447","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"29447","Ordinal":"1","NoteData":"Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"29447","Ordinal":"2","NoteData":"2021-04-15","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"29447","Ordinal":"3","NoteData":"2021-09-20","Type":"Other","Title":"Modified"}]}}}