CVE-2022-3590
MEDIUM EXPLOITED IN THE WILD NUCLEIWordPress 4.2-6.1.1 - Unauthenticated Blind SSRF via Pingback TOCTOU Race Condition
Title source: llmExploitation Summary
CVE-2022-3590 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 3 public exploits from researchers including hxlxmj, huynhvanphuc. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a Python script that scans WordPress websites for the CVE-2022-3590 vulnerability, which involves an unauthenticated blind SSRF in the pingback feature. The script checks for WordPress version, pingback feature availability, and sends a crafted XML-RPC request to determine vulnerability.
Description
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
Exploits (3)
This repository contains a Python script that scans WordPress websites for the CVE-2022-3590 vulnerability, which involves an unauthenticated blind SSRF in the pingback feature. The script checks for WordPress version, pingback feature availability, and sends a crafted XML-RPC request to determine vulnerability.
This repository contains a Python script that scans WordPress websites for the CVE-2022-3590 vulnerability, which involves an unauthenticated blind SSRF in the pingback feature. The script checks for WordPress version, pingback feature availability, and sends a crafted payload to determine vulnerability.
This repository contains a Python script that scans WordPress websites for the CVE-2022-3590 vulnerability, which involves an unauthenticated blind SSRF in the pingback feature. The script checks for WordPress version, pingback feature availability, and sends a crafted XML-RPC request to test for vulnerability.
Nuclei Templates (1)
cpe:"cpe:2.3:a:wordpress:wordpress" || http.component:"wordpress"
body="oembed" && body="wp-"
References (2)
Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N