CVE-2018-3811 | Oturia Smart Google Code Inserter Plugin up to 3.4 on WordPress smartgooglecode.php saveGoogleAdWords $_POST["oId"] sql injection (EDB-43420 / ID 865818)
A vulnerability was found in Oturia Smart Google Code Inserter Plugin up to 3.4 on WordPress and classified as critical. Affected is the function saveGoogleAdWords of the file smartgooglecode.php. Executing manipulation of the argument $_POST["oId"] can lead to sql injection.
This vulnerability is registered as CVE-2018-3811. It is possible to launch the attack remotely. Furthermore, an exploit is available.
It is suggested to upgrade the affected component.