vulnerability

Wordpress: CVE-2023-22622: Uncontrolled Resource Consumption ('Resource Exhaustion')

Severity
6
CVSS
(AV:A/AC:M/Au:N/C:N/I:N/A:C)
Published
2023-01-05
Added
2023-01-23
Modified
2025-01-30

Description

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

Solution

wordpress-upgrade-6_1_2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.