CVE-2022-3590
WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
- Published
- Dec 14, 2022
- Updated
- Apr 21, 2025
- Assigning CNA
- WPScan
- Evidence observed
- Aug 8, 2026
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NLow · next 30 days
- Percentile
- 87.4%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
Sources
3Python script to detect unauthenticated blind SSRF (CVE-2022-3590) in WordPress pingback feature. Supports single URL and batch scanning with attacker-controlled domain callback.
This repository contains a Python script that checks WordPress websites for the CVE-2022-3590 vulnerability, which exploits an unauthenticated blind Server-Side Request Forgery (SSRF) in the WordPress pingback feature.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.