Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-10753

Опубликовано: 24 июн. 2026
Источник: nvd
CVSS3: 2.7
EPSS Низкий

Описание

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

EPSS

Процентиль: 20%
0.00281
Низкий

2.7 Low

CVSS3

Дефекты

Связанные уязвимости

CVSS3: 2.7
github
2 месяца назад

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

EPSS

Процентиль: 20%
0.00281
Низкий

2.7 Low

CVSS3

Дефекты