Executive brief
A vulnerability exists in the PDF Generator for WordPress plugin, which is used to convert website content into downloadable PDF documents. An attacker can exploit this flaw to force the web server to make unauthorized requests to internal or external systems. This could lead to the exposure of sensitive internal data or allow the server to be used as a proxy for further attacks against other services.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the WP Swings PDF Generator for WordPress plugin (versions <= 1.6.2). The flaw allows unauthenticated remote attackers to induce the server to perform arbitrary HTTP requests via the plugin's PDF generation functionality. This can be used to scan internal networks, access metadata services in cloud environments, or bypass firewalls to interact with internal services that are not publicly accessible. The vulnerability is addressed in version 1.6.3.
Affected products
- WP Swings PDF Generator for WordPress <= 1.6.2
Timeline
- 2026-04-30: other: Vulnerability reported by researcher dodoh4t
- 2026-07-08: patched: Patch released in version 1.6.3
- 2026-07-13: advisory: CVE published to NVD