PT-2026-47059 · Undefined · Undefined

·

CVE-2026-10753

·

Published

2026-06-05

·

Updated

2026-07-02

CVSS v3.1

2.7

Low

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Site Kit by Google WordPress plugin versions prior to 1.176.0
Description A broken access control flaw exists in a REST API write endpoint that fails to properly restrict access to administrators. This allows lower-privileged users, such as Editors who have been granted dashboard sharing access, to modify a site-wide setting that should be restricted to administrators. This issue affects over 5 million WordPress sites worldwide.
Recommendations Update to version 1.176.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2026-10753

Affected Products

Undefined