MEDIUM
WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
Published Dec 14, 2022
5.9
MEDIUMCVSS 3.1
EPSS 3.24%
Description
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
Affected products
-
- Version 4.1.30StatusaffectedConstraints<=6.1.1
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://blog.sonarsource.com/wordpress-core-unauthenticated-blind-ssrf/ ExploitThird Party Advisory
- https://wpscan.com/vulnerability/c8814e6e-78b3-4f63-a1d3-6906a84c1f11 exploitvdb-entrytechnical-descriptionThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://blog.sonarsource.com/wordpress-core-unauthenticated-blind-ssrf/ | ExploitThird Party Advisory | |
| https://wpscan.com/vulnerability/c8814e6e-78b3-4f63-a1d3-6906a84c1f11 | exploitvdb-entrytechnical-descriptionThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WPScan
Published Dec 14, 2022
Updated Apr 21, 2025
Reserved Oct 18, 2022
Link CVE-2022-3590
CISA Vulnrichment
Updated Apr 21, 2025