← Back to CVE List

CVE-2022-3590

Published: 2022-12-14T09:15Z
Last Modified: 2024-11-21T07:19Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt