> ## Documentation Index
> Fetch the complete documentation index at: https://rootea.es/llms.txt
> Use this file to discover all available pages before exploring further.

# Wordpress: CVE-2021-29447

> Vulnerability allow a authenticated user whith low privilages upload a malicious WAV file that could lead to remote arbitrary file disclosure and server-side re

# Wordpress: CVE-2021-29447

<p className="machine-summary"><span className="prompt"><code>\$ tldr</code></span> TryHackMe · Challenge · Easy</p>

<div className="machine-meta">
  | ·            | ·                                                         |
  | ------------ | --------------------------------------------------------- |
  | Plataforma   | TryHackMe                                                 |
  | Tipo         | Challenge                                                 |
  | Dificultad   | <span className="dbadge dbadge-easy">EASY</span>          |
  | Acceso       | 🟢 Free                                                   |
  | Tiempo medio | 45 min                                                    |
  | Usuarios     | 14.443                                                    |
  | Sala oficial | [Abrir](https://tryhackme.com/room/wordpresscve202129447) |
</div>

## Descripción

Vulnerability allow a authenticated user whith low privilages upload a malicious WAV file that could lead to remote arbitrary file disclosure and server-side request forgery (SSRF).

## Resolver la room

| Idioma  | Autor         | Formato     | Enlace                                                    |
| ------- | ------------- | ----------- | --------------------------------------------------------- |
| 🇬🇧 EN | **TryHackMe** | Lab oficial | [Abrir](https://tryhackme.com/room/wordpresscve202129447) |

## Recursos por skill

| Skill                            | Fuente     | Enlace                                                                                              |
| -------------------------------- | ---------- | --------------------------------------------------------------------------------------------------- |
| WordPress Exploitation           | HackTricks | [Abrir](https://book.hacktricks.wiki/en/network-services-pentesting/pentesting-web/wordpress.html)  |
| Server-Side Request Forgery      | HackTricks | [Abrir](https://book.hacktricks.wiki/en/pentesting-web/ssrf-server-side-request-forgery/index.html) |
| Cracking Hashes (hashcat / John) | HackTricks | [Abrir](https://book.hacktricks.wiki/en/generic-methodologies-and-resources/brute-force.html)       |

## Skills relacionadas

[WordPress Exploitation](/skills/wordpress-exploit) · [Server-Side Request Forgery](/skills/ssrf) · [Cracking Hashes (hashcat / John)](/skills/cracking-hashes)

***

## Comentarios y truquillos

¿Has resuelto la room por una vía distinta? Compártela aquí — los comentarios viven en [GitHub Discussions](https://github.com/FFuson/HTB_Writeups/discussions).

<div className="rootea-giscus-wrap" data-giscus-term="thm:tryhackme-wordpresscve202129447" data-giscus-lang="es" />

*Última actualización: 2026-05-09*

<script type="application/ld+json">
  {`{"@context":"https://schema.org","@type":"TechArticle","name":"Wordpress: CVE-2021-29447","headline":"Wordpress: CVE-2021-29447 — TryHackMe room index","url":"https://rootea.es/tryhackme/rooms/wordpresscve202129447","inLanguage":"es","about":[{"@type":"Thing","name":"TryHackMe"},{"@type":"Thing","name":"Challenge"}],"isPartOf":{"@type":"WebSite","name":"rootea.es","url":"https://rootea.es"},"author":{"@type":"Organization","name":"rootea.es"}}`}
</script>
