Description
WordPress Plugin Google Forms is prone to a server-side request forgery vulnerability. An attacker may leverage this issue to make the vulnerable server perform port scanning of hosts in internal or external networks; other attacks are also possible. WordPress Plugin Google Forms version 0.91 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 0.92 or latest
References
Related Vulnerabilities
WordPress Plugin MailUp newsletter sign-up form Security Bypass (1.3.2)
WordPress Plugin Ultimate Google Analytics Cross-Site Request Forgery (1.6.0)
Drupal Core 6.x Multiple Vulnerabilities (6.0 - 6.5)
WordPress Plugin W3 Total Cache Multiple Vulnerabilities (0.9.4.1)
WordPress Plugin Oi Yandex.Maps for WordPress Cross-Site Scripting (3.2.7)