The Search Atlas SEO WordPress plugin before 2.6.24 does...
Moderate severity
Unreviewed
Published
Sep 5, 2026
to the GitHub Advisory Database
•
Updated Sep 6, 2026
Description
Published by the National Vulnerability Database
Sep 5, 2026
Published to the GitHub Advisory Database
Sep 5, 2026
Last updated
Sep 6, 2026
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
References