Known CVE
WordPress <= 6.2 - Server Side Request Forgery
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
CVE-2022-3590
Medium2022CVSS 5.9CWE-367
cve2022 · wordpress · wpscan · ssrf · oast · oob · vkev · vuln
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website