PoC Index

CVE-2026-15252

MEDIUM 5.4EPSS 0.2%

The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.

CVSS v3.1
5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS
0.18% chance of exploitation in the next 30 days, 7th percentile
Published
2026-07-30

Proof-of-concept exploits (1)

References

Related