Description
WordPress Plugin Dropbox Folder Share is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Dropbox Folder Share version 1.9.7 is vulnerable; prior versions may also be affected.
Remediation
Disable and remove the plugin until a fix is available
References
Related Vulnerabilities
TwistedHTTP Request Splitting Vulnerability (CVE-2020-10109)
WordPress Plugin FourSquare Checkins Cross-Site Request Forgery (1.2)
WordPress Plugin BackWPup Cross-Site Scripting (3.2.3)
AbanteCart Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2022-26521)
WordPress Plugin Visual Link Preview Security Bypass (2.2.2)