Loading market data...
← Back to CVE feed

CVE-2026-15252

MEDIUM CVSS 5.4 View on NVD ↗

Description

The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Published: Jul 30, 2026 06:25 UTC Modified: Jul 30, 2026 15:16 UTC