CVE Database
/

CVE-2022-3590

Back to search

CVE-2022-3590

Published: Dec 14, 2022

Modified: Apr 21, 2025

PUBLISHED

Description

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

VendorProductVersions

WordPress

WordPress

affected
4.1.30 - <= 6.1.1

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now