important · Zero-click
getID3 1.9.26 still contains the PHP 7.x XXE path its advisory says it fixed.
Affects
getID3, a PHP audio/video metadata library embedded in web applications and vendored in WordPress core.
If XML-bearing media reaches XML2array(), failure to disable external entities is suppressed and parsing continues, permitting local-file reads or SSRF. We still do not have a demonstrated WordPress delivery path.
Detail and 4 sources
Chain to watch
XML-bearing media reaches getID3 XML2array() under PHP 7.x→↓Entity loading remains enabled after a suppressed failure→↓XML parsing resolves a local-file or network entity→↓A working path through WordPress core has not been demonstrated; upload permissions and handler reachability remain unresolved.
Unverified chainOn PHP 7.x WordPress with the byte-identical vendored file, upload a controlled WAV iXML fixture as each role with upload_files and instrument the RIFF parser and outbound entity resolution.
Sources
ResearchgetID3’s advisory says 1.9.26 fixes the XXE. The file in the 1.9.26 tag doesn’t, and WordPress ships a byte-identical copy – Severity DailyCode / PoCSilent failure of libxml_disable_entity_loader() enables XXE on PHP < 8.0 · Advisory · JamesHeinrich/getID3 · GitHubCode / PoCRelease v1.9.26-202609042051 · JamesHeinrich/getID3 · GitHubCode / PoCFix #505: Prevent silent XXE on PHP < 8.0 by Ikram-4 · Pull Request #506 · JamesHeinrich/getID3 · GitHub