Description
WordPress Plugin Site Kit by Google is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently become a Google Search Console owner, allowing them to modify sitemaps, remove pages from Google search engine result pages (SERPs), or facilitate black hat SEO campaigns. WordPress Plugin Site Kit by Google version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.0 or latest
References
Related Vulnerabilities
PHP Cryptographic Issues Vulnerability (CVE-2012-2143)
Internet Information Services Other Vulnerability (CVE-2000-0246)
MySQL CVE-2013-1570 Vulnerability (CVE-2013-1570)
WordPress Plugin Related Posts for WordPress Cross-Site Scripting (2.0.3)
Atlassian Jira Server-Side Request Forgery (SSRF) Vulnerability (CVE-2019-20408)