CVE-2026-15252
MEDIUM 5.4EPSS 0.2%
The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.
- CVSS v3.1
- 5.4 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L - EPSS
- 0.18% chance of exploitation in the next 30 days, 7th percentile
- Published
- 2026-07-30