Description
WordPress Plugin Print My Blog-Print, PDF, & eBook Converter is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Print My Blog-Print, PDF, & eBook Converter version 1.6.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6.6 or latest
References
http://dumpco.re/bugs/wp-plugin-print-my-blog-ssrf
https://plugins.svn.wordpress.org/print-my-blog/trunk/readme.txt
Related Vulnerabilities
Jenkins Uncontrolled Resource Consumption Vulnerability (CVE-2021-28165)
WordPress Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-5204)
Liferay Portal Incorrect Authorization Vulnerability (CVE-2024-25604)
OpenSSL Observable Differences in Behavior to Error Inputs Vulnerability (CVE-2018-5407)
WordPress Plugin WP Publication Archive 'file' Parameter Directory Traversal (2.3)