CVE-2026-62139
Received Received - Intake

Unauthenticated CSRF in Site Kit by Google

Vulnerability report for CVE-2026-62139, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-11

Last updated on: 2026-09-11

Assigner: Patchstack

Description

Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-11
Last Modified
2026-09-11
Generated
2026-09-12
AI Q&A
2026-09-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google site_kit to 1.186.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated Cross Site Request Forgery (CSRF) vulnerability affecting Site Kit by Google plugin for WordPress versions up to 1.186.0. It allows attackers to trick users into executing unwanted actions through crafted links or pages while leveraging the user's existing authentication.

Detection Guidance

Detection primarily involves checking the installed version of the Site Kit by Google plugin. Use WordPress admin to verify the plugin version or run SQL queries on the database to check the version stored in the wp_options table.

Impact Analysis

An attacker could force higher-privileged users to perform unintended actions on your WordPress site without their knowledge. This could include modifying settings, creating or deleting content, or changing user permissions if the victim has sufficient rights.

Compliance Impact

This CSRF vulnerability could potentially allow unauthorized actions to be performed on behalf of authenticated users, which may lead to data exposure or modification. For GDPR, this could impact compliance by risking unauthorized access to personal data. For HIPAA, it might compromise protected health information if exploited. However, the vulnerability requires user interaction and has low severity, so its direct impact on compliance depends on implementation and mitigation measures.

Mitigation Strategies

Update the Site Kit by Google plugin to version 1.187.0 or later immediately. This patched version resolves the CSRF vulnerability. Ensure automatic updates are enabled or manually update through the WordPress admin panel.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62139. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart