CVE-2023-22622: WordPress

Medium severity, CVSS 5.3. EPSS: 1.7% chance of exploitation in the next 30 days.

WordPress through 6.1.1 depends on unpredictable client visits to cause wp-cron.php execution and the resulting security updates, and the source code describes "the scenario where a site may not receive enough visits to execute scheduled tasks in a timely manner," but neither the installation guide nor the security guide mentions this default behavior, or alerts the user about security risks on installations with very few visits.

Affected products

  • WordPress WordPress: up to and including 6.1.1

Published 2023-01-05. Last modified 2026-06-17.