CVE-2026-15252

CVE-2026-15252CVE-2026-15252

Description

The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX handlers, allowing any authenticated user such as a Subscriber to invoke the site's Google Indexing API integration, submitting or removing the site's URLs from Google's index and consuming its indexing quota.

Scoring

CVSS 5.4 ()
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Last modified2026-07-30
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.