Description
WordPress Plugin Print My Blog-Print, PDF, & eBook Converter is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Print My Blog-Print, PDF, & eBook Converter version 1.6.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6.6 or latest
References
http://dumpco.re/bugs/wp-plugin-print-my-blog-ssrf
https://plugins.svn.wordpress.org/print-my-blog/trunk/readme.txt
Related Vulnerabilities
MediaWiki Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-6335)
Magento Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-7942)
Highcharts JS Incorrect Regular Expression Vulnerability (CVE-2018-20801)
WordPress Plugin Kama WP Smiles Unspecified Vulnerability (1.8.1)