VYPR
Unrated severityNVD Advisory· Published Sep 5, 2026

Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion

CVE-2026-15247

Description

The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.