Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Public_Exploit-1--Wordpress-CVE-2021-29447 — CVE-2021-29447 is an authenticated XML External Entity (XXE) vulnerability in WordPress | Kitploit
Tools/GitHubGitHub/kashyapghodasara/public_exploit-1--wordpress-cve-2021-29447
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringWeb SecurityPenetration Testing
GitHubkashyapghodasara/public_exploit-1--wordpress-cve-2021-29447

Public_Exploit-1--Wordpress-CVE-2021-29447

CVE-2021-29447 is an authenticated XML External Entity (XXE) vulnerability in WordPress

View Repository
3h 18m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Public_Exploit-1--Wordpress-CVE-2021-29447

CVE-2021-29447 is an authenticated XML External Entity (XXE) vulnerability in WordPress

The vulnerability exists in the WordPress Media Library when WordPress is running on PHP 8 and the user has permission to upload media files. A specially crafted .wav file can cause WordPress to process malicious XML and resolve external entities. This can lead to:

● Arbitrary File Disclosure — reading files from the target server.
● Server-Side Request Forgery (SSRF) — making requests from the WordPress server.
● Exposure of sensitive information such as database credentials from wp-config.php.

● WordPress fixed this vulnerability in version 5.7.1.

Credit -

PoC.py : Isa Ebrahim - 0xRar
Wordpawn : wetw0rk

Download Tool