Smart Google Code Inserter < 3.5 - Unauthenticated SQL Injection
critical
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] va...
- CVSS:
- 9.8
- Affected:
- up to 3.5
- Fixed in:
- 3.5
- Disclosed:
- Jan 1, 2018
CVE-2018-3811 on NVD →
Smart Google Code Inserter < 3.5 - Stored Cross-Site Scripting
high
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php...
- CVSS:
- 7.2
- Affected:
- up to 3.5
- Fixed in:
- 3.5
- Disclosed:
- Jan 1, 2018
CVE-2018-3810 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database