Vulnerability record · CVE-2021-29447 · published 15 April 2021
CVE-2021-29447: WordPress Media Library XXE via file upload on PHP 8
Wordpress · Wordpress
WordPress Media Library mishandles XML parsing of uploaded files when the site runs on PHP 8, allowing an XML external entity (XXE) attack. A user with upload rights, such as an Author, can trigger it through the upload flow. It matters because it exposes internal files to a low-privileged authenticated user, and it was fixed in WordPress 5.7.1 plus minor releases for older branches.
Description
Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityPublic exploit material and a very high EPSS score make this readily exploitable, though it requires an authenticated upload-capable account and PHP 8.
What it is
WordPress Media Library mishandles XML parsing of uploaded files when the site runs on PHP 8, allowing an XML external entity (XXE) attack. A user with upload rights, such as an Author, can trigger it through the upload flow. It matters because it exposes internal files to a low-privileged authenticated user, and it was fixed in WordPress 5.7.1 plus minor releases for older branches.
Impact
An attacker with upload capability can read internal files on the server through XXE, gaining access to data outside the intended upload scope. The CVSS vector shows high confidentiality impact with no integrity or availability effect.
Attack surface
Reached over the network through the WordPress Media Library upload feature; it requires an authenticated account with file upload permission (Author level or above) and no user interaction beyond the upload. It only applies to installations running PHP 8.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.857 probability, 99.7th percentile) and multiple references are tagged Exploit, indicating public exploit material exists. No ransomware group use is documented.
What to do
- Upgrade WordPress to 5.7.1 or the latest minor release for your branch, and keep auto-updates enabled.
- Apply the Debian security update (DSA-4896) if WordPress is installed from Debian packages.
- Restrict file upload privileges so only trusted roles can upload to the Media Library.
- Disable external entity resolution in PHP XML parsing where feasible, or avoid running WordPress on PHP 8 until patched.
Detection
- Review web server and WordPress logs for uploads of XML-bearing files (for example MP3 or other media containing XML) by low-privileged users.
- Monitor for outbound or local file access patterns consistent with XXE, such as requests referencing file:// or unexpected entity expansion.
- Audit user roles and recent upload activity for Author-level accounts performing unusual media uploads.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2021-29447 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-29447), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.