WordPress is affected by an unauthenticated blind SSRF in...
Moderate severity
Unreviewed
Published
Dec 14, 2022
to the GitHub Advisory Database
•
Updated Apr 21, 2025
Description
Published by the National Vulnerability Database
Dec 14, 2022
Published to the GitHub Advisory Database
Dec 14, 2022
Last updated
Apr 21, 2025
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
References