Description
WordPress Plugin Site Kit by Google is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently become a Google Search Console owner, allowing them to modify sitemaps, remove pages from Google search engine result pages (SERPs), or facilitate black hat SEO campaigns. WordPress Plugin Site Kit by Google version 1.7.1 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 1.8.0 or latest
References
Related Vulnerabilities
Oracle Database Server CVE-2014-4292 Vulnerability (CVE-2014-4292)
WordPress Plugin Relevant-Related Posts by BestWebSoft Cross-Site Scripting (1.1.9)
LimeSurvey Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2021-44967)
Joomla! Core 3.x.x Information Disclosure (3.0.0 - 3.9.19)
WordPress Plugin Blog2Social:Social Media Auto Post & Scheduler Unspecified Vulnerability (5.1.2)