VYPR

Site Kit by Google

by WordPress

CVEs (2)

  • CVE-2020-8934MedJul 7, 2023
    risk 0.28cvss 4.3epss 0.00

    The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.8.0 This is due to the lack of capability checks on the admin_enqueue_scripts action which displays the connection key. This makes it possible for…

  • CVE-2026-10753LowJun 24, 2026
    risk 0.18cvss 2.7epss 0.00

    The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress…