Impact
The vulnerability exists in the Search Atlas SEO WordPress plugin version 2.6.24 and earlier. The plugin fails to enforce a nonce or verify user capabilities before handling a settings update in an early-priority action hook. Consequently, any authenticated user—including those with Subscriber role—can invoke the handler and overwrite or delete the site's Google service‑account credentials. This leads to credential compromise, which could allow the attacker to impersonate the site in Google services, disrupt SEO functionality, or gain access to sensitive data that the service account protects. The weakness reflects improper authorization protection.
Affected Systems
The affected product is the Search Atlas SEO WordPress plugin, any installation running a version older than 2.6.24. The vendor is listed as Unknown:Search Atlas SEO. The plugin stores Google service‑account credentials that are modified by the vulnerable handler.
Risk and Exploitability
An attacker only needs to be logged into the site with a valid account, even one with Subscriber authority, to trigger the missing check. The lack of a nonce or capability verification permits direct overwriting or deletion of the credentials. Although EPSS data is not available, the CVE is not listed in the CISA KEV catalog. The potential for credential loss indicates a high impact. The vulnerability allows unauthorized modification of security-sensitive configuration, and the exploited handler runs during an early priority, making the attack straightforward for a legitimate user.
OpenCVE Enrichment