CVE-2022-3590

All FrameworksWordPressCWE-OtherCVE-2022-3590

CVE-2022-3590

State: PUBLISHED · Published: 2022-12-14 · Updated: 2025-04-21 · Assigner: WPScan
Description
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
CWE
Affected
CVSS
References
Source
cvelistV5-main/cves/2022/3xxx/CVE-2022-3590.json