CVE-2022-3590

WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding

WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.


We have discovered 2,095,918 live websites that are affected by CVE-2022-3590.

Test my site




Affected Software

Product  WordPress
Category Content Management System
Vulnerable Domains2,095,918 live websites (22.74% of WordPress install base)
Vulnerable Versions
  • from 4.1.30 through 6.1.1
Vulnerable Versions Count478 versions ( 51.34% of all versions)


Common Weakness Enumeration

CWE-918 Server-Side Request Forgery (SSRF)



Details

  • Published - Dec 14, 2022
  • Updated - Aug 3, 2024

Credits

  • Thomas Chauchefoin (finder)
  • WPScan (coordinator)

CVE-2022-3590 usage by Country

United States550,305 websites



Germany235,930 websites
Japan219,370 websites
France129,685 websites
Russia100,252 websites
Poland73,800 websites
GB65,182 websites
Netherlands54,123 websites
Italy51,440 websites
Spain50,615 websites

CVE-2022-3590 usage by TLD

.com838,139 websites
.de120,135 websites
.ru87,326 websites
.org79,731 websites
.net66,256 websites
.pl59,087 websites
.nl49,209 websites
.jp47,634 websites
.fr45,617 websites
.co.uk45,282 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2022-3590

Top websites that are affected by CVE-2022-3590. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.org Singapore***
*****************.com United States***
****.br Brazil***
****.******.com Singapore***
*********.com United States***
*********.net United States***
**********.ca Canada*,***
************.***.ar Argentina*,***
*********.com Italy*,***
********.com Singapore*,***
See full domain list

FAQ

CVE-2022-3590 is Server-Side Request Forgery (SSRF) in WordPress
A total of 2,095,918 websites have been identified as vulnerable to CVE-2022-3590, discovered through global website indexing conducted by WebTechSurvey.
WordPress is susceptible to CVE-2022-3590 vulnerability.
WordPress versions before, and including, 6.1.1 are vulnerable to CVE-2022-3590.