Description
WordPress Plugin Site Kit by Google is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently become a Google Search Console owner, allowing them to modify sitemaps, remove pages from Google search engine result pages (SERPs), or facilitate black hat SEO campaigns. WordPress Plugin Site Kit by Google version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.0 or latest
References
Related Vulnerabilities
WordPress Plugin WordPress Content Slide Multiple Vulnerabilities (1.4.2)
Oracle Database Server CVE-2011-2322 Vulnerability (CVE-2011-2322)
WordPress Plugin Simple File Downloader Cross-Site Scripting (1.0.4)
Liferay Portal Session Fixation Vulnerability (CVE-2023-47798)
WordPress Plugin OneSignal-Web Push Notifications Cross-Site Scripting (1.17.7)