WP Core Vulnerability APR 2021:
Authenticated XXE Within the Media Library Affecting PHP 8
For your WordPress protection, be informed about the LATEST WP Core Vulnerability APR 2021. Publicly known since its first official report on 2022-04-15 or it's official disclosure on 2022-04-28. All versions of WordPress starting with 5.6-5.7 have the Authenticated XXE Within the Media Library Affecting PHP 8 vulnerability.
WordPress 5.6-5.7 - Authenticated XXE Within the Media Library Affecting PHP 8
CVE-2021-29447
References: Changeset 29378
- WordPress 5.6-5.7 CORE Authenticated XXE Within the Media Library Affecting PHP 8
- Use the software that powers over 41% of the web. Active installations: 41% of the ENTIRE INTERNET minus the updated instances of 5.7.1, since released on April 15, 2022.
Impact - What can an attacker do:
A user with the ability to upload files (like an Author) can exploit an XML parsing issue in the Media Library leading to XXE attacks. WordPress used an audio parsing library called ID3 that was affected by an XML External Entity (XXE) vulnerability affecting PHP versions 8 and above.