CVE-2022-3590
MEDIUM EXPLOITED IN THE WILD NUCLEIWordPress - Blind SSRF
Title source: llmDescription
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
Exploits (3)
nomisec
SCANNER
8 stars
by hxlxmj · infoleak
https://github.com/hxlxmj/CVE-2022-3590-WordPress-Vulnerability-Scanner
nomisec
SCANNER
by huynhvanphuc · infoleak
https://github.com/huynhvanphuc/CVE-2022-3590-WordPress-Vulnerability-Scanner
Nuclei Templates (1)
WordPress <= 6.2 - Server Side Request Forgery
MEDIUMVERIFIEDby riteshs4hu
Shodan:
cpe:"cpe:2.3:a:wordpress:wordpress" || http.component:"wordpress"
FOFA:
body="oembed" && body="wp-"
Scores
CVSS v3
5.9
EPSS
0.9115
EPSS Percentile
99.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation Intel
VulnCheck KEV
2024-09-18
InTheWild.io
2024-09-18
Classification
CWE
CWE-367
Status
published
Affected Products (2)
wordpress/wordpress
< 6.1.1
wordpress/wordpress
Timeline
Published
Dec 14, 2022
Tracked Since
Feb 18, 2026