Back to search
CVE-2022-3590
Published: Dec 14, 2022
Modified: Apr 21, 2025
PUBLISHED
Description
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
| Vendor | Product | Versions |
|---|---|---|
WordPress | WordPress | affected 4.1.30 - <= 6.1.1 |
References
https://wpscan.com/vulnerability/c8814e6e-78b3-4f63-a1d3-6906a84c1f11
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now