Description
The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.
Published: 2026-07-30
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Search Atlas SEO WordPress plugin before version 2.6.12 fails to perform a capability or nonce check in one of its AJAX handlers. As a result, any authenticated user—such as a site subscriber—can trigger the plugin’s integration with the Google Indexing API. This allows the user to submit or remove the site’s URLs from Google’s index and consume the site's allotted indexing quota without proper authorization. The impact is that an attacker could de‑index the site or exhaust Google’s free quota, adversely affecting search visibility and potentially redirecting search traffic.

Affected Systems

WordPress sites running the Search Atlas SEO plugin with a version older than 2.6.12. The vulnerability is mitigated by updating to v2.6.12 or later, which adds the missing capability check. The plugin is distributed by an unknown author and is available through the WordPress plugin repository.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity. The EPSS score of less than 1% points to a very low chance that an exploit has been observed in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to be logged in to the site with at least the subscriber role. Attackers can perform the malicious request directly via AJAX endpoints over the network, so protection through network segmentation or WAF rules may reduce the risk. The lack of a nonce or capability check means the privilege escalation is straightforward for authenticated users.

Generated by OpenCVE AI on August 3, 2026 at 11:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Search Atlas SEO plugin to version 2.6.12 or later to restore the proper capability verification.
  • Revoke or remove the capability that allows AJAX indexing from low‑privilege roles such as Subscriber, using a role editor plugin or custom code, to prevent uninvolved users from accessing the endpoint.
  • Configure a Web Application Firewall (WAF) rule or .htaccess restriction to block or rate‑limit requests to the vulnerable AJAX endpoint until a patch is applied, reducing the chance of exploitation.

Generated by OpenCVE AI on August 3, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Search Atlas Group
Search Atlas Group search Atlas Seo
Wordpress
Wordpress wordpress
Vendors & Products Search Atlas Group
Search Atlas Group search Atlas Seo
Wordpress
Wordpress wordpress

Thu, 30 Jul 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.
Title Search Atlas SEO < 2.6.12 - Subscriber+ Google Indexing API Access
References

Subscriptions

Search Atlas Group Search Atlas Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-07-30T14:50:24.510Z

Reserved: 2026-07-09T12:38:54.313Z

Link: CVE-2026-15252

cve-icon Vulnrichment

Updated: 2026-07-30T14:47:55.410Z

cve-icon NVD

Status : Deferred

Published: 2026-07-30T06:25:01.940

Modified: 2026-07-30T15:16:26.587

Link: CVE-2026-15252

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T11:15:04Z

Weaknesses