CVE-2023-22622
MEDIUM 5.3EPSS 1.7%
WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS
- 1.66% chance of exploitation in the next 30 days, 75th percentile
- Published
- 2023-01-05
- Updated
- 2025-04-07
Proof-of-concept exploits (3)
- michael-david-fry/CVE-2023-226224★ · 2024-08-02
- michael-david-fry/wp-cron-smash4★ · 2024-08-02
- Th3g4ntl3m4n/Abusing-wp-cron