CVE-2022-3590 is an unauthenticated blind Server-Side Request Forgery (SSRF) vulnerability affecting WordPress, specifically within its pingback feature. Due to a Time-of-Check to Time-of-Use (TOCTOU) race condition, attackers can bypass validation checks to access internal network resources. Rated with a CVSS score of 5.9 (MEDIUM) and a FAUCET Risk Score of 99/100, this vulnerability has a high potential for confidentiality impact (C:H) despite requiring high attack complexity (AC:H). While there is no evidence of active exploitation, Metasploit modules, or ExploitDB entries, a Nuclei template exists for detection, and there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.30, <= 6.1.1CPE match | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
>= 4.2, <= 6.1.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
4.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:4.1:-:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.