The google-document-embedder plugin before 2.6.2 for WordPress has CSRF.
No PoCs from references.
- https://github.com/20142995/nuclei-templates