The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
CVE-2026-15247
NONE
EPSS 0.14%
Updated Sep 05, 2026
Google
CVE Details
CVE ID
CVE-2026-15247
Published Date
Sep 05, 2026
Vendor
Google
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.8th percentile (higher than 3.8% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory