WordPress Plugin Vulnerabilities

Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion

Description

The plugin does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.

Proof of Concept

Affects Plugins

Fixed in 2.6.24

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
Shivamani Vastrala
Submitter
Shivamani Vastrala
Verified
Yes

Timeline

Publicly Published
2026-09-03 (about 2 days ago)
Added
2026-09-03 (about 1 day ago)
Last Updated
2026-09-03 (about 1 day ago)

Other