CVE-2026-10753 PUBLISHED

Site Kit by Google < 1.176.0 - Editor+ Email Reporting Settings Update

Assigner: WPScan
Reserved: 03.06.2026 Published: 24.06.2026 Updated: 24.06.2026

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

Product Status

Vendor Unknown
Product Site Kit by Google
Versions Default: unaffected
  • affected from 0 to 1.176.0 (excl.)

Credits

  • Shashank finder
  • WPScan coordinator

References

Problem Types

  • CWE-863 Incorrect Authorization CWE