CVE-2022-3590

WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.


We have discovered 1,332,538 live websites that are affected by CVE-2022-3590.

Run a Free Instant Scan




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains1,332,538 live websites (17% of WordPress install base)
Vulnerable Versions
  • from 4.1.30 through 6.1.1
Vulnerable Versions Count539 versions ( 36% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Dec 14, 2022
  • Updated - Apr 21, 2025

Credits

  • Thomas Chauchefoin (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2022-3590
United States274,649 websites



Japan162,599 websites
Germany128,379 websites
Italy70,868 websites
France70,779 websites
Russia67,315 websites
Poland46,663 websites
GB45,057 websites
Spain37,416 websites
Netherlands35,707 websites

Website Distribution by TLD

Number of websites using CVE-2022-3590
.com521,199 websites
.de75,720 websites
.ru55,257 websites
.org50,296 websites
.it46,695 websites
.net42,625 websites
.pl35,467 websites
.jp35,271 websites
.nl29,863 websites
.fr28,563 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-3590

Top websites that are affected by CVE-2022-3590. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
*****************.com United States***
****.br Brazil***
*****.net Canada***
**********.com United States***
*********.net United States***
**********.ca Canada*,***
*********.com Italy*,***
********.com Singapore*,***
************.com United States*,***
See full domain list

FAQ

CVE-2022-3590 is Server-Side Request Forgery (SSRF) in WordPress
A total of 1,332,538 websites have been identified as vulnerable to CVE-2022-3590, based on global website indexing conducted by WebTechSurvey.
The WordPress is affected by the CVE-2022-3590 vulnerability.
WordPress versions up to and including 6.1.1 are vulnerable to CVE-2022-3590.