CVE-2023-22622

MEDIUMCVSS 5.3/10EPSS 1.66%

Last modified

CVE-2023-22622 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.. EPSS estimates a 1.66% chance of exploitation in the next 30 days.

Description

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

Metrics

CVSS 3.1
5.3/10

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
1.66%

73.7th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
WordpressWordpress<= 6.1.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2023-22622?
WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.
How severe is CVE-2023-22622?
CVE-2023-22622 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 1.66% probability of exploitation in the next 30 days.
How do I fix CVE-2023-22622?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2023-22622?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST