Impact
An unauthenticated Cross‑Site Request Forgery flaw exists in WordPress Site Kit by Google plugin versions 1.186.0 and earlier. By sending a forged request from a victim’s browser, an attacker may trigger any action that the plugin exposes. If the user is logged in with administrative privileges, the attacker could potentially modify site settings, alter data, or perform other administrative operations. The vulnerability is a classic error in handling request tokens and is identified as CWE‑352.
Affected Systems
WordPress sites running the Google Site Kit plugin for WordPress, version 1.186.0 or earlier, are vulnerable. All sites that have installed any of those versions are at risk until the plugin is updated beyond 1.186.0.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. Exploitation requires the victim to be authenticated to the WordPress admin, while the attacker only needs to embed a crafted request in a malicious page or use social engineering. The EPSS score of less than 1% and the absence from the CISA KEV catalog suggest a low public exploitation probability, yet the flaw remains exploitable once the conditions are met. The potential impact on confidentiality, integrity, or availability is limited to the actions the plugin permits but can still affect administrative controls and site configuration.
OpenCVE Enrichment