Description
WordPress is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress versions ranging from 3.7 and up to (and including) 6.1.1 are vulnerable.
Remediation
Block/Turn off access to XMLRPC/pingbacks as per researchers recommandation
References
https://blog.sonarsource.com/wordpress-core-unauthenticated-blind-ssrf/
https://sploitus.com/exploit?id=WPEX-ID:C8814E6E-78B3-4F63-A1D3-6906A84C1F11
Related Vulnerabilities
PHP CVE-2006-5706 Vulnerability (CVE-2006-5706)
WordPress Plugin External 'Video for Everybody' Cross-Site Scripting (2.0)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2043)
MySQL Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-2922)