The Google Doc Embedder plugin for WordPress is vulnerable to Server Side Request Forgery via the 'gview' shortcode in versions up to, and including, 2.6.4. This can allow authenticated attackers with contributor-level permissions or above to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 08 Apr 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Google Doc Embedder <= 2.6.4 - Authenticated (Contributor+) Blind Server Side Request Forgery | |
| Weaknesses | CWE-918 |
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:01:25.135Z
Reserved: 2024-01-03T10:54:06.966Z
Link: CVE-2024-0216
Updated: 2024-08-01T17:41:16.217Z
Status : Awaiting Analysis
Published: 2024-04-30T02:15:06.383
Modified: 2026-04-08T18:18:48.407
Link: CVE-2024-0216
No data.
OpenCVE Enrichment
No data.