S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 16, 2023

CVE-2018-3810 Scanner

CVE-2018-3810 scanner - Authentication Bypass vulnerability in Oturia Smart Google Code Inserter plugin for WordPress

Est. Time~15 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2018-3810
9.8
CVSS

Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

The Oturia Smart Google Code Inserter plugin is a widely-used plugin for WordPress that allows users to insert custom Google Analytics tracking codes into their website. It is a handy tool for tracking website traffic and user engagement. The plugin works by inserting the Google Analytics code into the website's header, thereby enabling website administrators to track and analyze website traffic data.

However, this seemingly useful plugin is not immune to vulnerabilities. The CVE-2018-3810 vulnerability detected in the Oturia Smart Google Code Inserter plugin before version 3.5 allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The vulnerability is due to the fact that the smartgooglecode.php script that houses the saveGoogleCode() function does not check if the current request is made by an authorized user. This means that any unauthenticated user can successfully update the inserted code, posing a significant risk to the website's security.

The exploitation of this vulnerability can lead to dire consequences for website owners. The arbitrary code inserted by the attacker can potentially compromise the website's security by stealing user credentials, installing malware, or even taking over the entire website. Malicious actors can also use this vulnerability to inject malicious code into the website, causing it to redirect to a malicious site or even perform denial-of-service attacks.

In conclusion, website owners must be vigilant in protecting their digital assets from vulnerabilities that threaten their website's security. At s4e.io, our platform provides a comprehensive solution for website owners to quickly and easily learn about vulnerabilities and protect their digital assets. Our pro features enable users to scan their website for vulnerabilities and provide actionable recommendations to mitigate and fix them. Protect yourself from vulnerabilities today by signing up for our platform!

 

REFERENCES

Solution Advice

Website owners who use the Oturia Smart Google Code Inserter plugin can take several precautions to protect themselves from this vulnerability. They include:

  • Updating the plugin to version 3.5 or above, which has fixed the vulnerability.
  • Removing the vulnerable plugin from the website if they are unable to update it.
  • Regularly checking their website's code for any suspicious changes or unauthorized access.
  • Restricting access to their website's backend to authorized personnel only.
  • Utilizing a web application firewall to prevent unauthorized code injections.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.