Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.
AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateREVIEWED
AI priorityNONE
AI confidence93%
Public exploitation · VTP factUNKNOWN
Assessment
Smart Google Code Inserter before 3.5 lacks an authorization check in saveGoogleCode(), allowing unauthenticated insertion of JavaScript or HTML across a WordPress site. The record is critical (CVSS 9.8) with EPSS 0.91141, but no exploit or exploitation evidence is supplied.
Why it matters
Injected code can run on every page served by the affected WordPress installation.
Site-wide script control can affect visitors and administrative users.
Evidence
1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.
Uncertainties
Affected plugin deployment and endpoint exposure are unknown.
EPSS is predictive; exploit availability, public exploitation, and first-party observation remain unknown.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Next watchpoint
Plugin versions below 3.5.
AI baseline history (1)
BASELINE ASSESSED
Smart Google Code Inserter authentication bypassgpt-5.6-sol · high
Evidence confidence0%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
EPSS is 0.91; this is predictive context, not exploitation evidence.
02
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
02
Material change ledger
What changed
No material changes are recorded for this subject.
03
Claim provenance
Evidence and source independence
0publications detected
0underlying evidence chains
0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.
First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.