CVE-2021-29447 is an XML external entity (XXE) vulnerability in the WordPress Media Library. On WordPress installations running PHP 8, an authenticated user permitted to upload media, including an Author-role user, can submit crafted upload content that reaches vulnerable XML parsing. External entity resolution can be abused to read internal files accessible to the web-server process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
9 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This eight-file repository combines an operational CVE-2021-29447 blind XXE proof of concept with supporting lab artifacts and an independent WordPress malicious-plugin generator. PoC.py accepts an attacker listener address/port and a file path, generates payload.wav and evil.dtd, and starts PHP's built-in HTTP server. A vulnerable PHP 8 WordPress Media Library parser retrieves the DTD, reads the selected local file through PHP stream filters, and returns compressed/base64 data in a callback request. decode.php and decode_for_db.php contain captured payload decoders; evil.dtd is a configured example targeting wp-config.php; hash.txt contains a WordPress password hash. wordpawn_rev_shell.py is not the CVE exploit itself: it invokes msfvenom to package a Meterpreter reverse shell and GET-command webshell into a plugin ZIP, representing a post-authentication/post-privilege-escalation RCE stage. The write-up explicitly distinguishes this plugin shell stage from the XXE disclosure vulnerability.
This repository is a small standalone proof-of-concept/operational exploit for CVE-2021-29447, a WordPress XXE issue affecting WAV/iXML parsing as described by the repository. The main exploit logic is in `CVE-2021-29447.sh`, a Bash script that accepts attacker host (`-l`), port (`-p`), and a target file path (`-f`). It generates two artifacts: `payload.wav`, which embeds an XXE DOCTYPE referencing an attacker-controlled external DTD, and `evil.dtd`, which defines entities to read an arbitrary server-side file through the PHP stream wrapper `php://filter/zlib.deflate/read=convert.base64-encode/resource=...` and exfiltrate the result to `http://<attacker>:<port>/?p=...`. The script then launches `python3 -m http.server` on the chosen port to serve the DTD and receive the target’s outbound HTTP request. The exploit’s primary capability is arbitrary file read from the vulnerable WordPress host, contingent on the attacker being able to get the crafted WAV processed and on outbound connectivity from the target to the attacker server. This is not a detection script; it is an actual exploitation utility with a hardcoded but functional exfiltration workflow, so OPERATIONAL is the best fit. Supporting files are minimal: `decode.php` is a helper that decodes exfiltrated data by applying base64 decode and zlib decompression, though it contains a placeholder string and requires the operator to paste captured data manually. `docker-compose.yml` provides a local lab environment with `wordpress:5.7.0-php8.0` exposed on port 8080 and a MySQL 8.0 backend, indicating the repository is intended both for demonstration and testing. `README.md` documents setup, usage, and the attack technique. Overall, the repository structure is simple and purpose-built: one exploit script, one decode helper, one test environment definition, and one explanatory README.
Repository is a proof-of-concept for CVE-2021-29447 (WordPress getID3 XXE) enabling arbitrary file disclosure when WordPress 5.6–5.7 runs on PHP 8.0+. Structure: (1) docker-compose.yml spins up a vulnerable lab (wordpress:5.7.0-php8.0 + mysql:5.7) exposed on localhost:8080. (2) evil.dtd contains the core XXE payload: it reads /etc/passwd via php://filter with zlib.deflate + base64 encoding and defines an entity that triggers an HTTP request back to the attacker with the data in parameter p. (3) README.md documents creating a malicious WAV iXML chunk that references the remote DTD (http://YOUR_IP:PORT/evil.dtd), uploading it as an authenticated Author+ user, and decoding the returned base64+deflate data. (4) exploit.py is not a direct exploit against WordPress; it is an attacker-side helper that starts a local PHP built-in web server (php -S 0.0.0.0:PORT) to host evil.dtd (and optionally payload.wav) and observe incoming exfiltration requests. Overall capability: authenticated XXE-triggered file read with HTTP exfiltration; no RCE or persistence implemented.
This repository provides a proof-of-concept exploit for CVE-2021-29447, an authenticated XXE vulnerability in the WordPress Media Library (versions 5.6 to 5.7, PHP 8 required). The repository contains three files: a LICENSE, a README.md with detailed vulnerability and usage information, and a Bash script (payload.sh) that automates the attack. The script generates a malicious WAV file with an embedded XXE payload and a DTD file, sets up a Python HTTP server to receive exfiltrated data, logs into the target WordPress instance, retrieves a CSRF nonce, uploads the malicious file, and waits for the server to exfiltrate the contents of a specified file (default: /etc/passwd) to the attacker's listener. The exploit requires valid WordPress credentials and a listener set up by the attacker. The code is a functional proof-of-concept and demonstrates the vulnerability's impact (arbitrary file disclosure and potential SSRF).
This repository contains a Python script (expl.py) and a README.md. The script generates a malicious WAV file with an iXML chunk containing an XXE payload. The payload is designed to exploit XML External Entity vulnerabilities in applications (notably WordPress BookingPress Plugin < 1.0.11) that parse iXML metadata in WAV files. The exploit works by having the target load an attacker-hosted DTD file, which then causes the target to exfiltrate arbitrary file contents via HTTP GET requests to the attacker's server. The README provides detailed usage instructions, workflow diagrams, and references to the relevant CVE and vulnerability database entries. The exploit is a proof-of-concept for file exfiltration via XXE in WAV iXML metadata, requiring the attacker to host a DTD file and monitor for exfiltrated data.
This repository contains a Python proof-of-concept exploit for CVE-2021-29447, an authenticated XML External Entity (XXE) vulnerability in WordPress versions 5.6 and 5.7. The exploit abuses the way WordPress parses WAV file metadata (specifically the iXML chunk) to trigger an out-of-band (OOB) XXE attack. The attacker must have valid WordPress credentials with media upload permissions. The script generates a malicious WAV file that references a remote DTD hosted on the attacker's HTTP server. When the file is uploaded to WordPress, the server fetches the DTD, which instructs it to read and exfiltrate arbitrary files (such as /etc/passwd or wp-config.php) back to the attacker's server via HTTP callbacks. The exploit supports both interactive and batch (wordlist) modes, and can optionally use an external HTTP server. Exfiltrated files are saved in the 'dump/' directory, and generated DTDs are stored in 'dtd/'. The repository consists of three files: a license, a README with detailed usage instructions, and the main exploit script ('exploit_CVE-2021-29447.py').
This repository provides a proof-of-concept exploit for CVE-2021-29447, an XXE vulnerability in WordPress 5.6 and 5.7 (with PHP 8) that allows an authenticated attacker to exfiltrate arbitrary files from the server. The main exploit script (CVE-2021-29447.py) is a Python program that acts as both an HTTP server (to serve a malicious DTD and receive exfiltrated data) and a client (to authenticate to the target WordPress instance and upload a specially crafted WAV file containing the XXE payload). The exploit requires valid WordPress credentials and network access between the target and the attacker's HTTP server. The docker-compose.yml file provides a test environment for WordPress 5.7.0 with PHP 8. The README.md contains detailed usage instructions and an example. The exploit demonstrates file exfiltration by retrieving /etc/passwd from the target. The attack vector is network-based, leveraging HTTP endpoints on the target WordPress instance.
This repository is a proof-of-concept exploit for CVE-2021-29447, a WordPress XML parsing issue in the Media Library that leads to an XXE (XML External Entity) vulnerability. The exploit targets WordPress versions 5.6 and 5.7 (prior to 5.7.1) running on PHP 8, and requires the attacker to have file upload privileges (such as an Author role). The main script, PoC.py, automates the creation of a malicious WAV file (payload.wav) containing an XXE payload that references a remote DTD (evil.dtd) hosted by the attacker. When the payload is uploaded to the WordPress Media Library, the vulnerable server parses the XML, fetches the attacker's DTD, and is tricked into reading a local file (e.g., /etc/passwd). The file's contents are base64-encoded, zlib-compressed, and exfiltrated via a GET request to the attacker's server. The repository also includes a PHP script (decode.php) to decode the exfiltrated data. The exploit demonstrates a classic XXE file read and exfiltration attack, with clear instructions and automation for ease of use.
This repository is a proof-of-concept exploit for CVE-2021-29447, an authenticated XXE (XML External Entity) vulnerability in WordPress versions 5.6 and 5.7 when running on PHP 8.0. The exploit allows an attacker with Author+ privileges to upload a specially crafted WAV file containing a malicious iXML chunk. This chunk references an attacker-controlled DTD (evil.dtd) hosted on a web server (typically at http://host.docker.internal:8001/evil.dtd). The DTD is designed to read and exfiltrate the contents of sensitive files (such as /etc/passwd) from the server using PHP filters and base64 encoding. The repository includes scripts to generate the malicious WAV file (in JavaScript using wavefile), a sample DTD, and a Docker Compose setup to run a vulnerable WordPress instance for testing. The main attack vector is network-based, leveraging file upload and external entity resolution. The repository is structured with clear separation between the attacker's tools (malicious_wav, evil.dtd) and the test environment (docker-compose.yml).
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A specific CVE listed among vulnerabilities described as weaponized and accompanied by public proof-of-concept code in the actors' toolset.
A specific CVE referenced as weaponized within the actors' toolset; the content does not describe the flaw type or affected product.
A WordPress vulnerability incorporated into the crew's public-exploit toolset.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.