Description
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
Published: 2026-09-05
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authorization bypass leading to credential compromise
Action: Immediate Patch
AI Analysis

Impact

The vulnerability exists in the Search Atlas SEO WordPress plugin version 2.6.24 and earlier. The plugin fails to enforce a nonce or verify user capabilities before handling a settings update in an early-priority action hook. Consequently, any authenticated user—including those with Subscriber role—can invoke the handler and overwrite or delete the site's Google service‑account credentials. This leads to credential compromise, which could allow the attacker to impersonate the site in Google services, disrupt SEO functionality, or gain access to sensitive data that the service account protects. The weakness reflects improper authorization protection.

Affected Systems

The affected product is the Search Atlas SEO WordPress plugin, any installation running a version older than 2.6.24. The vendor is listed as Unknown:Search Atlas SEO. The plugin stores Google service‑account credentials that are modified by the vulnerable handler.

Risk and Exploitability

An attacker only needs to be logged into the site with a valid account, even one with Subscriber authority, to trigger the missing check. The lack of a nonce or capability verification permits direct overwriting or deletion of the credentials. The CVSS score of 5.4 indicates a moderate risk, and the EPSS score of <1% suggests a low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The potential for credential loss indicates a significant impact, as unauthorized modification of security‑sensitive configuration could allow an attacker to impersonate the site in Google services, disrupt SEO functionality, or compromise data protected by the service account. The exploited handler runs during an early priority, making the attack straightforward for a legitimate user.

Generated by OpenCVE AI on September 6, 2026 at 15:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Search Atlas SEO plugin to version 2.6.24 or later, which includes the nonce and capability checks.
  • After updating, verify that the Google service‑account credentials have not been altered unintentionally and, if needed, re‑enter them through the settings screen.
  • Restrict access to the plugin's settings page and code that handles credential storage to users with Administrator capability; consider adding role restrictions or custom capability checks for Subscribers.

Generated by OpenCVE AI on September 6, 2026 at 15:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Search Atlas Group
Search Atlas Group search Atlas Seo
Wordpress
Wordpress wordpress
Vendors & Products Search Atlas Group
Search Atlas Group search Atlas Seo
Wordpress
Wordpress wordpress

Sun, 06 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-352

Sun, 06 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 05 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285
CWE-352

Sat, 05 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
Title Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion
References

Subscriptions

Search Atlas Group Search Atlas Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-06T10:45:55.145Z

Reserved: 2026-07-09T12:12:25.408Z

Link: CVE-2026-15247

cve-icon Vulnrichment

Updated: 2026-09-06T10:33:57.756Z

cve-icon NVD

Status : Deferred

Published: 2026-09-05T07:17:10.693

Modified: 2026-09-08T19:09:21.310

Link: CVE-2026-15247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:15:14Z

Weaknesses