CVE-2022-3590
- Reference to the description:
- Description:
- WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
- Last updated date:
- 12/20/2022
Reports
ACTIVELY EXPLOITED
- Type:
- exploitation
- Confidence:
- HIGH
- Date of publishing:
- 09/18/2024
- Reference url to background
https://media.defense.gov/2024/Sep/18/2003547016/-1/-1/1/CSA-PRC-LINKED-ACTORS-BOTNET.PDF
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 12/16/2022
- Reference url to background
https://blog.sonarsource.com/wordpress-core-unauthenticated-blind-ssrf/
- Type:
- exploit
- Confidence:
- HIGH
- Date of publishing:
- 06/12/2023
- Reference url to background
https://github.com/hxlxmjxbbxs/CVE-2022-3590-WordPress-Vulnerability-Scanner