CVE-2026-15247
N/A
N/A
Summary
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Search Atlas SEO | 0 < 2.6.24 | affected |
Weaknesses
- CWE-862 Missing Authorization
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.