Vulnerability Description
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oturia | Smart Google Code Inserter | < 3.5 |
Related Weaknesses (CWE)
References
- https://limbenjamin.com/articles/smart-google-code-inserter-auth-bypass.htmlExploitThird Party Advisory
- https://wordpress.org/plugins/smart-google-code-inserter/#developersRelease NotesThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8987Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43420/ExploitThird Party AdvisoryVDB Entry
- https://limbenjamin.com/articles/smart-google-code-inserter-auth-bypass.htmlExploitThird Party Advisory
- https://wordpress.org/plugins/smart-google-code-inserter/#developersRelease NotesThird Party Advisory
- https://wpvulndb.com/vulnerabilities/8987Third Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/43420/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-3810?
CVE-2018-3810 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgo...
How severe is CVE-2018-3810?
CVE-2018-3810 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2018-3810?
Check the references section above for vendor advisories and patch information. Affected products include: Oturia Smart Google Code Inserter.