First published: Thu Jan 05 2023(Updated: )
WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress WordPress | <=6.1.1 | |
<=6.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-22622.
The severity of CVE-2023-22622 is medium, with a severity value of 5.3.
WordPress versions up to and including 6.1.1 are affected by CVE-2023-22622.
CVE-2023-22622 relies on unpredictable client visits to cause execution of wp-cron.php and trigger security updates.
To mitigate CVE-2023-22622, ensure that your WordPress site receives enough visits to execute scheduled tasks in a timely manner.