Unrated severityNVD Advisory· Published Sep 5, 2026
Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion
CVE-2026-15247
Description
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <2.6.24
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/1618ba19-c410-440b-a2d9-1e1526614549/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.