CVE-2022-44593 LOW

CVE-2022-44593: WordPress Solid Security plugin <= 9.3.1 - IP Spoofing Leading to Denial of Service vulnerability

Vendor Solidwp
Product Solid Security
Weakness CWE-348
Published June 21, 2024
Last update April 28, 2026

CVSS base score

3.7/10
Attack vector Network
Attack complexity High
Privileges required None
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

Use of Less Trusted Source vulnerability in SolidWP Solid Security allows HTTP DoS.This issue affects Solid Security: from n/a through 9.3.1.

Explanation of Vulnerability in Simple Terms

02Summary

Solid Security versions up to 9.3.1 contain a flaw that allows an attacker to cause a denial of service condition. The vulnerability requires specific network conditions and timing to exploit, making it difficult to trigger reliably. No authentication is required, but the impact is limited to temporary unavailability rather than data loss or compromise.

What an attacker can do

03Attacker Capabilities

Cause temporary unavailability or performance degradation of the site.

Potential impact on your site

04Site Impact

Your site may experience brief downtime or slowness, but data and user accounts remain secure.

Conditions required to exploit

05Prerequisites

Network access; specific timing or conditions required to trigger the flaw.

Key dates

06Disclosure timeline

June 21, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE