CVE-2026-15247
Search Atlas SEO < 2.6.24 - Subscriber+ Google Service Account Credential Overwrite/Deletion
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
| Vendor | unknown |
| Product | search atlas seo |
| Published | Sep 5, 2026 |
| Last Updated | Sep 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown search atlas seo
Be the first to know when new medium vulnerabilities affecting unknown search atlas seo are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Search Atlas SEO
0 < 2.6.24
References
Credits
Shivamani Vastrala WPScan