Medium severity5.9NVD Advisory· Published Dec 14, 2022· Updated Jun 17, 2026
CVE-2022-3590
CVE-2022-3590
Description
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: >=4.2,<=6.1.1
- cpe:2.3:a:wordpress:wordpress:4.1:-:*:*:*:*:*:*
- (no CPE)
- (no CPE)range: 4.1.30
- osv-coords2 versions
>= 4.1.0, < 4.1.1+ 1 more
- (no CPE)range: >= 4.1.0, < 4.1.1
- (no CPE)range: >= 4.1.0, < 4.1.1
Patches
Vulnerability mechanics
References
2- blog.sonarsource.com/wordpress-core-unauthenticated-blind-ssrf/nvdExploitThird Party Advisory
- wpscan.com/vulnerability/c8814e6e-78b3-4f63-a1d3-6906a84c1f11nvdThird Party Advisory
News mentions
0No linked articles in our index yet.