Back

CVE-2018-3810

CRITICAL

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.

Published: Jan 1, 2018 Modified: Jun 17, 2026
CWE-287

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
oturia smart_google_code_inserter * < 3.5

GitHub Security Advisory GHSA-f59r-v67m-78wf

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5...

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 91.14%

Top 0% most likely to be exploited

Threat Score 76.5 / 100

Data Sources

NVD EPSS GitHub