plugin

Smart Google Code Inserter Vulnerabilities

2 known security issues reported for the Smart Google Code Inserter WordPress plugin. Most recent disclosed Jan 1, 2018.

1 critical 1 high

Running Smart Google Code Inserter on your site? Check whether your installed version is affected.

Scan your site free

Smart Google Code Inserter < 3.5 - Unauthenticated SQL Injection

critical

SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] va...

CVSS:
9.8
Affected:
up to 3.5
Fixed in:
3.5
Disclosed:
Jan 1, 2018

CVE-2018-3811 on NVD →

Smart Google Code Inserter < 3.5 - Stored Cross-Site Scripting

high

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php...

CVSS:
7.2
Affected:
up to 3.5
Fixed in:
3.5
Disclosed:
Jan 1, 2018

CVE-2018-3810 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database