WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
We have discovered 2,095,918 live websites that are affected by CVE-2022-3590.
Product | |
Category | Content Management System |
Vulnerable Domains | 2,095,918 live websites (22.74% of WordPress install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 478 versions ( 51.34% of all versions) |
![]() | 550,305 websites |
![]() | 235,930 websites |
![]() | 219,370 websites |
![]() | 129,685 websites |
![]() | 100,252 websites |
![]() | 73,800 websites |
![]() | 65,182 websites |
![]() | 54,123 websites |
![]() | 51,440 websites |
![]() | 50,615 websites |
.com | 838,139 websites |
.de | 120,135 websites |
.ru | 87,326 websites |
.org | 79,731 websites |
.net | 66,256 websites |
.pl | 59,087 websites |
.nl | 49,209 websites |
.jp | 47,634 websites |
.fr | 45,617 websites |
.co.uk | 45,282 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
************.org | ![]() | *** | |
*****************.com | ![]() | *** | |
****.br | ![]() | *** | |
****.******.com | ![]() | *** | |
*********.com | ![]() | *** | |
*********.net | ![]() | *** | |
**********.ca | ![]() | *,*** | |
************.***.ar | ![]() | *,*** | |
*********.com | ![]() | *,*** | |
********.com | ![]() | *,*** |
FAQ