Vulnerabilities > Oturia > Smart Google Code Inserter > 3.4

DATE CVE VULNERABILITY TITLE RISK
2018-01-01 CVE-2018-3811 SQL Injection vulnerability in Oturia Smart Google Code Inserter
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server.
network
low complexity
oturia CWE-89
7.5
2018-01-01 CVE-2018-3810 Improper Authentication vulnerability in Oturia Smart Google Code Inserter
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress.
network
low complexity
oturia CWE-287
7.5