{"error":0,"message":null,"data":{"name":"Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed","plugin":"google-site-kit","link":"https:\/\/wordpress.org\/plugins\/google-site-kit\/","latest":"1788805020","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"43353581c268785da77eb9e5447462398ff1a27b64fd523e1bbe54f9499e5762","name":"Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"b9b7ace7c8988b97aac899303cb3b7f012df932f","name":"WordPress Site Kit by Google plugin <= 1.7.1 - Privilege Escalation vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/google-site-kit\/vulnerability\/wordpress-site-kit-by-google-plugin-1-7-1-privilege-escalation-vulnerability","description":"Privilege Escalation vulnerability found by Chloe Chamberland in WordPress Site Kit by Google plugin (versions <= 1.7.1).","date":"2020-05-13"}],"impact":[]},{"uuid":"903751c17ee428c8597fbe7fe9297e53d8f59c390ce2190e3240df33623769a1","name":"Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"6aac99ec913d183de2f9c4649f2eb663fd071c83","name":"Site Kit by Google <= 1.7.1 - Sensitive Information Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/google-site-kit\/site-kit-by-google-171-sensitive-information-disclosure","description":"The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.7.1. This is due to the lack of capability checks on the admin_enqueue_scripts action which displays the connection key. This makes it possible for authenticated attackers with any level of access obtaining owner access to a site in the Google Search Console.","date":"2020-05-21"},{"id":"CVE-2020-8934","name":"CVE-2020-8934","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-8934","description":"[en] The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.8.0 This is due to the lack of capability checks on the admin_enqueue_scripts action which displays the connection key. This makes it possible for authenticated attackers with any level of access obtaining owner access to a site in the Google Search Console. We recommend upgrading to V1.8.1 or above.","date":"2023-07-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-252","name":"Unchecked Return Value","description":"The product does not check the return value from a method or function, which can prevent it from detecting unexpected states and conditions."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"577853d938875c0d5f149d011abdf53a0ba3d7a95995455baa1f0e16fc22aa91","name":"Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.8.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.8.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"9c1d386f-a55b-4042-8f1b-f37c508cdeb1","name":"Site Kit by Google &lt; 1.8.0 - Privilege Escalation to gain Search Console Access","link":"https:\/\/wpscan.com\/vulnerability\/9c1d386f-a55b-4042-8f1b-f37c508cdeb1","description":"This flaw allows any authenticated user, regardless of capability, to become a Google Search Console owner for any site running the Site Kit by Google plugin.","date":null}],"impact":[]},{"uuid":"3fce445e4308c48776e4797d81bc2c8ed8057a7625e7d2c0aaf1c2f03dbe1b07","name":"Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.176.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.176.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-10753","name":"CVE-2026-10753","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-10753","description":"[en] The Site Kit by Google  WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google  WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.","date":"2026-06-24"},{"id":"7ba7eb16dfdc344d8c5510d3a7f4296be0fcaccb","name":"WordPress Site Kit by Google Plugin < 1.176.0 is vulnerable to Settings Change","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/google-site-kit\/vulnerability\/wordpress-site-kit-by-google-plugin-1-176-0-editor-email-reporting-settings-update-vulnerability","description":"<p>WordPress Site Kit by Google Plugin < 1.176.0 is vulnerable to Settings Change<\/p><p>Software: Site Kit by Google<\/p><p>Fixed in version 1.176.0 <\/p><p>Affected Version < 1.176.0<\/p><p>CVE: CVE-2026-10753<\/p>","date":"2026-06-25"},{"id":"fdcd9ec5f9549c5411d78f9d636507cb0fb83328","name":"Site Kit by Google \u2013 Analytics, Search Console, AdSense, Speed < 1.176.0 - Missing Authorization to Authenticated (Editor+) Settings Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/google-site-kit\/site-kit-by-google-analytics-search-console-adsense-speed-11760-missing-authorization-to-authenticated-editor-settings-update","description":"The Site Kit by Google \u2013 Analytics, Search Console, AdSense, Speed plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to 1.176.0 (exclusive). This makes it possible for authenticated attackers, with Editor-level access and above, to perform an unauthorized action.","date":"2026-06-25"}],"impact":{"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fa69eb5e246fab16f65c392919f45fcc8ac9efb4f9fa012cfa7b906b16da3387","name":"Site Kit by Google &#8211; Analytics, Search Console, AdSense, Speed [google-site-kit] < 1.187.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.187.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-62139","name":"CVE-2026-62139","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-62139","description":"[en] Unauthenticated Cross Site Request Forgery (CSRF) in Site Kit by Google <= 1.186.0 versions.","date":"2026-09-11"},{"id":"a93424a83c64cfc4a9a16549769de50333b632b0","name":"Site Kit by Google \u2013 Analytics, Search Console, AdSense, Speed <= 1.186.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/google-site-kit\/site-kit-by-google-analytics-search-console-adsense-speed-11860-cross-site-request-forgery","description":"The Site Kit by Google \u2013 Analytics, Search Console, AdSense, Speed plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.186.0. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-06-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789645247"}