Sploitus

CVE-2016-2222

No indexed exploits for CVE-2016-2222 yet

The wp_http_validate_url function in wp-includes/http.php in WordPress before 4.4.2 allows remote attackers to conduct server-side request forgery (SSRF) attacks via a zero value in the first octet of an IPv4 address in the u parameter to wp-admin/press-this.php.

Affected products
Wordpress
Wordpress
= 4.4.1
Fix
Available
CVSS 3.0
8.6 HIGH
EPSS
9.0% (95th percentile)
NVD status
Modified
Published
2016-05-22
CVE-2016-2222 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2016-2222 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2016-2222 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.