The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.
CVE-2026-15252
NONE
EPSS 0.14%
Updated Jul 30, 2026
Google
CVE Details
CVE ID
CVE-2026-15252
Published Date
Jul 30, 2026
Vendor
Google
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.14%
Likelihood of exploitation in next 30 days
Percentile:
3.7th percentile (higher than 3.7% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory