Beveiligingsadvies

CVE-2022-3590

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2022-12-14 08:33:40
Laatst bijgewerkt 2025-04-21 14:12:02
Toegewezen door WPScan
CVSS-score 5.9
Status PUBLISHED

Beschrijving

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.