Impact
The PDF Generator for WordPress plugin contains a server‑side request forgery vulnerability. By providing arbitrary URLs during PDF generation, an attacker can cause the WordPress server to perform requests to those addresses. This functionality could expose internal network services, retrieve sensitive information, or interact with back‑end systems. The weakness corresponds to CWE‑918.
Affected Systems
All releases of the WP Swings PDF Generator for WordPress plugin with a version number less than or equal to 1.6.2. No further affected versions are listed in the CVE disclosure.
Risk and Exploitability
The CVSS score of 7.2 reflects a medium‑to‑high risk level, while an EPSS score of less than 1% indicates that the probability of exploitation is currently low. The vulnerability is not included in the CISA KEV catalog. The likely attack vector is via the plugin’s web interface or API, requiring the attacker to supply URLs that trigger PDF generation. Successful exploitation could lead to unauthorized network access or data exfiltration from internal resources.
OpenCVE Enrichment