CVE-2021-29447General(debian / debian_linux)

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Wordpress is an open source CMS. A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. This requires WordPress installation to be using PHP 8. Access to internal files is possible in a successful XXE attack. This has been patched in WordPress version 5.7.1, along with the older affected versions via a minor release. We strongly recommend you keep auto-updates enabled.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • wordpress

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • General: 4 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-23); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
debian_linuxwordpress

2 versions affected across 2 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-23: 1Mentions · 2026-05-06: 1Mentions · 2026-05-10: 1Mentions · 2026-06-15: 1PoC Mentioned / Linked · 2026-05-06: 1Technical Details · 2026-02-23: 1Technical Details · 2026-05-06: 102-2305-0605-1006-15
Signal classification1 categories
General
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Rikuxx@Rikuxx00
    General

    記事を投稿しました! TryHackMe Writeup: Wordpress: CVE-2021-29447 on #Qiita https://qiita.com/rikum0730/items/4a76c7f6d8825f10c493?utm_campaign=post_article&utm_medium=twitter&utm_source=twitter_share

    Post summary

    The tweet announces a Qiita article about WordPress CVE‑2021‑29447 but provides no further details on exploitation, patches, or technical specifics.

    0001098
    168 followersView on X
  • Himadri Singh@LittleSun4lower
    General

    Completed Wordpress: CVE-2021-29447 room on TryHackMe! https://tryhackme.com/room/wordpresscve202129447?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #learning #consistency

    Post summary

    The user finished a TryHackMe room that covers CVE-2021-29447, with no further details about exploitation or remediation.

    0001032
    9 followersView on X
  • あおち@ye5384
    General

    @tryhackme I just completed Wordpress: CVE-2021-29447 room on TryHackMe! Vulnerability allow a authenticated user whith low privilages upload a malicious WAV file that could lead to remote arbitrary file disclosure and server-side request forgery (SSRF). https://tryhackme.com/room/wordpresscve202129447?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=67c5a2369a2064b00449c4e6 #tryhackme

    Post summary

    User shares completion of a TryHackMe room on CVE‑2021‑29447, describing how low‑privilege authenticated users can upload malicious WAV files to achieve arbitrary file disclosure and SSRF.

    1000070
    20 followersView on X
  • KK@kk0128_
    General

    I just completed Wordpress: CVE-2021-29447 room on TryHackMe! Vulnerability allow a authenticated user whith low privilages upload a malicious WAV file that could lead to remote arbitrary file disclosure and SSRF. https://tryhackme.com/room/wordpresscve202129447?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=621772229e33c30050c7bc9b #tryhackme via @tryhackme

    Post summary

    A TryHackMe room on CVE‑2021‑29447 is highlighted, describing a file‑upload flaw that permits arbitrary file disclosure and SSRF, but no active exploitation or patches are mentioned.

    00000116
    532 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSdebiandebian_linux9.0--
Appwordpresswordpress---

Explore more