Skip to finding
important · Zero-click

getID3 1.9.26 still contains the PHP 7.x XXE path its advisory says it fixed.

Affects

getID3, a PHP audio/video metadata library embedded in web applications and vendored in WordPress core.

If XML-bearing media reaches XML2array(), failure to disable external entities is suppressed and parsing continues, permitting local-file reads or SSRF. We still do not have a demonstrated WordPress delivery path.

Detail and 4 sources
Chain to watch
XML-bearing media reaches getID3 XML2array() under PHP 7.x→↓Entity loading remains enabled after a suppressed failure→↓XML parsing resolves a local-file or network entity→↓A working path through WordPress core has not been demonstrated; upload permissions and handler reachability remain unresolved.
Unverified chainOn PHP 7.x WordPress with the byte-identical vendored file, upload a controlled WAV iXML fixture as each role with upload_files and instrument the RIFF parser and outbound entity resolution.
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Tuesday, September 22, 2026