PT-2023-11950 · Google · Site Kit By Google
Published
2023-07-07
·
Updated
2023-07-14
·
CVE-2020-8934
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
The Site Kit by Google plugin for WordPress versions up to, and including, 1.8.0
Description
The issue is related to Sensitive Information Disclosure due to the lack of capability checks on the
admin enqueue scripts action, which displays the connection key. This allows authenticated attackers with any level of access to obtain owner access to a site in the Google Search Console.Recommendations
For versions up to, and including, 1.8.0, upgrade to V1.8.1 or above.
As a temporary workaround, consider restricting access to the
admin enqueue scripts action until a patch is available.Fix
Unchecked Return Value
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Site Kit By Google