Unpredictable Client Visit Dependency in WordPress wp-cron.php
CVE-2023-22622

5.3MEDIUM

Key Information:

Vendor

Wordpress

Status
Vendor
CVE Published:
5 January 2023

What is CVE-2023-22622?

The vulnerability affects WordPress versions up to 6.1.1, where the wp-cron.php relies on unpredictable client visits to execute security updates via scheduled tasks. This dependency creates a scenario where sites with low traffic may not receive necessary updates in a timely manner, leaving them vulnerable. The absence of proper documentation concerning this behavior enhances the risk, as users may not be alerted to the potential security implications of minimal site visits.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

EPSS Score

10% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.