← back
CVE-2018-3811

CVE-2018-3811

35Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 43%
from disclosure to weapon2 days
Published on NVDJan 1
1st PoC+2d
exploitation probability
43%top 1% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] variable before passing it as input into the SQL query.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.