PT-2026-95736 · WordPress · Seo Booster

·

CVE-2026-15660

·

Published

2026-09-19

·

Updated

2026-09-19

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SEO Booster versions prior to 7.4.8
Description The SEO Booster plugin for WordPress contains a missing authorization flaw. The handle oauth callback() function, which is hooked to admin init, fails to perform a capability check when processing the access token and google email parameters from the $ GET array. This allows authenticated users with Subscriber-level access or higher to visit a crafted /wp-admin/ URL to overwrite the seobooster access token, seobooster google email, and seobooster gsc sites options, and delete the seobooster needs reauth flag. This action disrupts the Google Search Console integration and enables the injection of attacker-controlled data into site options via a token that triggers an outbound Google API request.
Recommendations Update SEO Booster to version 7.4.8 or later. As a temporary mitigation, restrict access to the /wp-admin/ area for users with Subscriber-level roles.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15660

Affected Products

Seo Booster