CVE-2026-15247
Received Received - Intake

Stored Credentials Modification in Search Atlas SEO WordPress Plugin

Vulnerability report for CVE-2026-15247, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-05

Last updated on: 2026-09-05

Assigner: WPScan

Description

The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-05
Last Modified
2026-09-05
Generated
2026-09-05
AI Q&A
2026-09-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
search_atlas seo to 2.6.24 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Search Atlas SEO WordPress plugin before version 2.6.24 has a vulnerability where it does not check for proper authorization before allowing users to update settings. This means any logged-in user, even with basic Subscriber access, can overwrite or delete the site's Google service account credentials.

Detection Guidance

Check if the Search Atlas SEO WordPress plugin version is below 2.6.24. Log in as a Subscriber or higher and attempt to modify or delete Google service-account credentials via plugin settings. Monitor for unauthorized changes to these credentials.

Impact Analysis

An attacker with Subscriber access could delete or modify your Google service account credentials, potentially disrupting services that rely on those credentials. This could lead to loss of access to Google services integrated with your WordPress site.

Compliance Impact

This vulnerability could lead to unauthorized access or deletion of sensitive data, which may violate compliance requirements under GDPR or HIPAA if such data is involved. Proper access controls are essential for maintaining compliance.

Mitigation Strategies

Update the Search Atlas SEO plugin to version 2.6.24 or later immediately. Review plugin settings for unauthorized changes to Google service-account credentials. Restrict Subscriber-level access if not required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15247. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart