THREAT OPS › Threat News › [NVD] CVE-2026-15247 — The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google servic
[NVD] CVE-2026-15247 — The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google servic
CVE-2026-15247 CVSS: None Published: 2026-09-05T07:17:10.693
The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers, allowing any authenticated user such as a Subscriber to overwrite or delete the site's stored Google service-account credentials.
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- CVE-2026-15247cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15247