Description
WordPress Plugin Google Doc Embedder is prone to an arbitrary file disclosure vulnerability because it fails to properly sanitize user-supplied input. An attacker can exploit this vulnerability to view local files in the context of the web server process, which may aid in launching further attacks. WordPress Plugin Google Doc Embedder version 2.4.6 is vulnerable; other versions may also be affected.
Remediation
Update to plugin version 2.5.4 or latest
References
http://www.securityfocus.com/bid/57133/exploit
http://ceriksen.com/2013/01/03/wordpress-google-document-embedder-arbitrary-file-disclosure/
Related Vulnerabilities
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.12)
WordPress Plugin Count per Day 'notes.php' Cross-Site Scripting (3.2.3)
WordPress Plugin Import all XML, CSV & TXT into WordPress Server-Side Request Forgery (6.5.2)
WordPress Plugin Customer Service Software & Support Ticket System Cross-Site Scripting (5.5.1)
Plone CMS Server-Side Request Forgery (SSRF) Vulnerability (CVE-2021-33510)