WordPress is affected by an unauthenticated blind SSRF in the pingback feature. Because of a TOCTOU race condition between the validation checks and the HTTP request, attackers can reach internal hosts that are explicitly forbidden. Does Imunify360 handle this attack?
- WordPress 6.1.1 and lower
imunify360-agent update modsec-rules --force