managed securityWP Core Vulnerability 2022

WP Core Vulnerability JAN 2023:

still no fix in latest version Version 6.1.1

For your WordPress protection, be informed about the LATEST WP Core Vulnerability JAN 2023. ALL WordPress versions are affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.

This vulnerability was reported to WordPress on January 21, 2022. Yeah, you read it correctly, a year ago! Yet it got “accepted publicly” and confirmed only October 10, 2022. CVE-2022-3590 proves that: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3590.

This issue was first reported about six years ago in January 2017 by another researcher and numerous others over the years. This was ignored throughout the years, as clean, stand-alone WP instance cannot be taken over without relying on other vulnerable services. Because of its low impact as-is, and the need to chain it to additional vulnerabilities in third-party software, everybody involved believes this issue won’t endanger WordPress users and can only FORCE them to harden their instances.

Yet, these needed additional vulnerabilities in third-party software ARE PRESENT at the hosting infrastructure level. To be protected, hosting needs to either convince you to disable default settings inside your WordPress – either to do it without your consent. If these are not real-life options, then in reality remains for you to either learn about these vulnerabilities and learn how to protect your WordPress or choose managed WP Security services, that are specifically for these “reappearing” cases.

Read more about this here: WordPress Core – Unauthenticated Blind SSRF.

 

managed WP/Woo SECURITY

Protect your WordPress from publicly reported cases of WP Core Vulnerability JAN 2023 BEFORE IT’S TOO LATE! You will also protect your customers, your reputation, your online business!

  • Unauthenticated Blind Server Side Request Forgery (SSRF) AFTER A YEAR still NOT FIXED in WordPress <= 6.1.1
    • WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden. This vulnerability was reported to WordPress on January 21; no fix is available yet.
    • Disable and block XMLRPC (pingback) feature!

wp core vulnerability jan 2023

Related Posts to WP Core Vulnerability:

WP Core Vulnerability JUN 2023: 6 patches

WP Core Vulnerability JUN 2023: For your WordPress protection, be informed about the LATEST WP Core Vulnerability JUN 2023 – all reported as fixed fix in WordPress 6.2.2 Security Release. WordPress 6.2.1 is now available! This minor release features 20 bug fixes in Core and 10 bug fixes for the block editor. WordPress 6.2.2 is…

WP Core Vulnerability NOV 2022: 15 bug fixes

WP Core Vulnerability NOV 2022: Version 6.0.3 For your WordPress protection, be informed about the LATEST WP Core Vulnerability NOV 2022. On October 17, 2022, WordPress 6.0.3 was released to the public. This release features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. The WordPress…

WP Core Vulnerability SEP 2022: 20 bug fixes

WP Core Vulnerability SEP 2022: Version 6.0.2 For your WordPress protection, be informed about the LATEST WP Core Vulnerability SEP 2022. On August 30, 2022, WordPress 6.0.2was released to the public. This security and maintenance release features 12 bug fixes on Core, 5 bug fixes for the Block Editor, and 3 security fixes. Because this…

9 bug fixes in WP Core Vulnerability MAY 2022: Caution

WP Core Vulnerability MAY 2022: Version 5.9.3 For your WordPress protection, be informed about the LATEST WP Core Vulnerability MAY 2022. On April 5, 2022, WordPress 5.9.3 was released to the public. This maintenance release features 9 bug fixes in Core and 10 bug fixes in the block editor. WordPress 5.9.3 is a short-cycle maintenance…

Contact us today for a WordPress or WooCommerce AUDIT!

Do you suspect any WP Core Vulnerability JAN 2023 Security Exploits within your WordPress?