Description
WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Database Backup Unspecified Vulnerability (4.1)
WordPress Plugin WP Support Plus Responsive Ticket System Multiple Vulnerabilities (4.1)
Joomla! Core 2.5.x Cross-Site Scripting (2.5.0 - 2.5.1)
WordPress Plugin WordPress Clean Up & Optimizer-Clean Up Optimizer SQL Injection (3.0.13)
WordPress Plugin Qwizcards-online quizzes and flashcards Cross-Site Scripting (3.36)