[wp-trac] [WordPress Trac] #57363: WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding

WordPress Trac noreply at wordpress.org
Wed Dec 21 01:09:26 UTC 2022


#57363: WP <= 6.1.1 - Unauthenticated Blind SSRF via DNS Rebinding
------------------------------+------------------------------
 Reporter:  edavis711         |       Owner:  (none)
     Type:  defect (bug)      |      Status:  new
 Priority:  normal            |   Milestone:  Awaiting Review
Component:  Pings/Trackbacks  |     Version:  6.1.1
 Severity:  normal            |  Resolution:
 Keywords:  needs-patch       |     Focuses:
------------------------------+------------------------------

Comment (by samiamnot):

 The issue is rated as a medium severity issue. It seemingly requires a
 vulnerability chain (unless there is another vulnerability to chain
 together, it is not exploitable). I am sure that the WP developers are
 actively working on a fix. See
 https://nvd.nist.gov/vuln/detail/CVE-2022-3590. If you are nervous, the
 vulnerability is in [https://codex.wordpress.org/XML-RPC_Support WordPress
 XML-RPC] and you can turn it off via a number of
 [https://wordpress.org/plugins/search/xml-rpc/ WordPress plugins].

-- 
Ticket URL: <https://core.trac.wordpress.org/ticket/57363#comment:3>
WordPress Trac <https://core.trac.wordpress.org/>
WordPress publishing platform


More information about the wp-trac mailing list