Unauthenticated Cross Site Request Forgery in Site Kit by Google Plugin
CVE-2026-62139
4.3MEDIUM
What is CVE-2026-62139?
The Site Kit by Google plugin versions up to 1.186.0 are susceptible to unauthenticated Cross Site Request Forgery (CSRF) attacks. This vulnerability could allow attackers to execute actions on behalf of users without their consent, potentially leading to unauthorized access and manipulation of user data. Organizations using this plugin should consider applying available security patches and updates to safeguard against such attacks.
Affected Version(s)
Site Kit by Google <= 1.186.0
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program