Description
WordPress is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress versions ranging from 3.7 and up to (and including) 6.1.1 are vulnerable.
Remediation
Block/Turn off access to XMLRPC/pingbacks as per researchers recommandation
References
https://blog.sonarsource.com/wordpress-core-unauthenticated-blind-ssrf/
https://sploitus.com/exploit?id=WPEX-ID:C8814E6E-78B3-4F63-A1D3-6906A84C1F11
Related Vulnerabilities
WordPress Plugin Brafton Cross-Site Scripting (3.4.7)
Oracle JRE CVE-2023-21830 Vulnerability (CVE-2023-21830)
WordPress Plugin WP Shop Multiple SQL Injection Vulnerabilities (3.4.3.15)
Oracle Application Server Other Vulnerability (CVE-2002-0560)
Django Uncontrolled Resource Consumption Vulnerability (CVE-2019-14233)