Vulnerability record · CVE-2018-3810 · published 1 January 2018
CVE-2018-3810: WordPress Smart Google Code Inserter plugin auth bypass allows code injection
Oturia · Smart Google Code Inserter
The Oturia Smart Google Code Inserter plugin before 3.5 for WordPress fails to verify that requests to its saveGoogleCode() function come from an authorized user. Any unauthenticated attacker can therefore update the stored code via the sgcgoogleanalytic parameter, injecting arbitrary JavaScript or HTML that is served on all WordPress pages.
Description
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with no authentication or user interaction, public exploit code, and a very high EPSS probability make this trivially exploitable and high impact.
What it is
The Oturia Smart Google Code Inserter plugin before 3.5 for WordPress fails to verify that requests to its saveGoogleCode() function come from an authorized user. Any unauthenticated attacker can therefore update the stored code via the sgcgoogleanalytic parameter, injecting arbitrary JavaScript or HTML that is served on all WordPress pages.
Impact
An attacker can persistently inject arbitrary JavaScript or HTML into every page of the site, enabling defacement, malicious redirects, credential or session theft, and drive-by attacks against all visitors. Because the injected code is stored and served site-wide, the effect is persistent rather than limited to a single request.
Attack surface
Reachable over the network through the plugin's saveGoogleCode() endpoint with no authentication and no user interaction required, as reflected by the CVSS vector AV:N/AC:L/PR:N/UI:N. The attacker only needs to send a request containing the sgcgoogleanalytic parameter.
Exploitation
Public exploit code is referenced (Exploit-DB 43420 and a third-party advisory tagged Exploit), and EPSS is very high at 0.91141 (99.8th percentile), though the CVE is not listed in CISA KEV.
What to do
- Update the Smart Google Code Inserter plugin to version 3.5 or later immediately.
- If the plugin is not required, deactivate and remove it to eliminate the vulnerable endpoint.
- Restrict or block unauthenticated access to the plugin's saveGoogleCode() endpoint at the web server or WAF.
- Audit the plugin's stored code setting (sgcgoogleanalytic) and remove any unauthorized JavaScript or HTML.
- Review WordPress user and content integrity for signs of tampering after exposure.
Detection
- Monitor web server and WAF logs for unauthenticated POST requests containing the sgcgoogleanalytic parameter.
- Inspect the plugin's stored code setting for unexpected or unauthorized JavaScript/HTML.
- Scan served WordPress pages for injected scripts or unexpected external references.
- Alert on changes to the plugin's configuration or stored code outside normal administrative activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://limbenjamin.com/articles/smart-google-code-inserter-auth-bypass.html | ExploitThird Party Advisory |
| https://wordpress.org/plugins/smart-google-code-inserter/#developers | Release NotesThird Party Advisory |
| https://wpvulndb.com/vulnerabilities/8987 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43420/ | ExploitThird Party AdvisoryVDB Entry |
| https://limbenjamin.com/articles/smart-google-code-inserter-auth-bypass.html | ExploitThird Party Advisory |
| https://wordpress.org/plugins/smart-google-code-inserter/#developers | Release NotesThird Party Advisory |
| https://wpvulndb.com/vulnerabilities/8987 | Third Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43420/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2018-3810 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-3810), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.