Description
WordPress Plugin Print My Blog-Print, PDF, & eBook Converter is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Print My Blog-Print, PDF, & eBook Converter version 1.6.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.6.6 or latest
References
http://dumpco.re/bugs/wp-plugin-print-my-blog-ssrf
https://plugins.svn.wordpress.org/print-my-blog/trunk/readme.txt
Related Vulnerabilities
Moodle Uncontrolled Resource Consumption Vulnerability (CVE-2021-32476)
WordPress CVE-2020-28033 Vulnerability (CVE-2020-28033)
WordPress Plugin Tickera-WordPress Event Ticketing Cross-Site Request Forgery (3.4.9.9)
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)
WordPress Plugin YITH Pre-Order for WooCommerce Security Bypass (1.1.9)