CVE-2022-3590
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/12/2022
Last modified:
21/04/2025
Description
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
Impact
Base Score 3.x
5.90
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | 4.2 (including) | 6.1.1 (including) |
| cpe:2.3:a:wordpress:wordpress:4.1:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



