CVE-2022-3590 is an unauthenticated blind server-side request forgery vulnerability in WordPress's pingback feature. According to the provided content, the issue arises from a time-of-check to time-of-use (TOCTOU) race condition between the pingback validation logic and the subsequent outbound HTTP request. Because the destination is validated before the actual request is issued, an attacker can exploit DNS rebinding to cause the request to resolve to a different address at use time, allowing access to internal hosts that WordPress is intended to block explicitly. The vulnerability is blind SSRF because the attacker can induce requests to attacker-chosen internal targets without necessarily receiving the full response body directly.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Small standalone Python proof-of-concept exploit for an unauthenticated blind SSRF condition in WordPress, described in the README as affecting WordPress 6.8-6.8.3 and 6.9-6.9.1 via XML-RPC pingback discovery. The repository is minimal: README.md documents the issue and usage, while main.py contains the full exploit logic. The script uses the requests library to POST a crafted XML-RPC methodCall to the target's /xmlrpc.php endpoint, invoking pingback.ping. It sets the attacker-controlled CALLBACK_URL as the source URL and a valid TARGET_POST URL on the victim WordPress site as the target URL. Successful exploitation is blind: the script checks the XML-RPC response for faultCode text but instructs the operator to verify success by observing inbound traffic at the callback endpoint. There is no post-exploitation payload, persistence, or shell access; the capability is limited to SSRF verification and identifying outbound connectivity/public IP behavior of the WordPress server.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.