Authentication Bypass Vulnerability in Oturia Smart Google Code Inserter Plugin
CVE-2018-3810
Key Information:
- Vendor
- Wordpress
- Vendor
- CVE Published:
- 1 January 2018
Badges
Summary
The Oturia Smart Google Code Inserter plugin for WordPress contains a significant vulnerability that enables unauthenticated attackers to exploit the 'sgcgoogleanalytic' parameter and insert arbitrary JavaScript or HTML code. This malicious code executes across all pages served by a vulnerable WordPress site, as the saveGoogleCode() function does not validate authorization before processing requests. The vulnerability exists in versions prior to 3.5 of the plugin, posing a considerable risk to website integrity and security.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
66% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved