CVE-2026-15660: CWE-862 Missing Authorization in cleverplugins SEO Booster
The SEO Booster plugin for WordPress up to version 7.4.7 has a missing authorization vulnerability in the handle_oauth_callback() function. This flaw allows authenticated users with Subscriber-level access or higher to manipulate site options related to Google Search Console integration by visiting a crafted admin URL. The vulnerability can disrupt integration and inject attacker-controlled data into site options.
AI Analysis
Technical Summary
CVE-2026-15660 is a missing authorization vulnerability (CWE-862) in the SEO Booster WordPress plugin versions up to and including 7.4.7. The handle_oauth_callback() function, hooked to admin_init, processes $_GET parameters 'access_token' and 'google_email' without verifying the caller's role or capabilities. This allows authenticated users with low privileges (Subscriber and above) to overwrite sensitive plugin options such as seobooster_access_token, seobooster_google_email, and seobooster_gsc_sites, and delete the seobooster_needs_reauth flag. The attacker-supplied token influences outbound Google API requests, and the plugin stores the API response, enabling injection of attacker-chosen data into site options.
Potential Impact
An attacker with Subscriber-level access or higher can disrupt the Google Search Console integration by overwriting plugin options and deleting flags, potentially injecting malicious or incorrect data into site options. This does not lead to direct confidentiality loss or denial of service but impacts integrity of plugin configuration and integration functionality.
Mitigation Recommendations
No patch or official fix is currently documented. Administrators should restrict user roles carefully to limit Subscriber-level access and above to trusted users. Monitor for updates from the vendor for an official fix. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
CVE-2026-15660: CWE-862 Missing Authorization in cleverplugins SEO Booster
Description
The SEO Booster plugin for WordPress up to version 7.4.7 has a missing authorization vulnerability in the handle_oauth_callback() function. This flaw allows authenticated users with Subscriber-level access or higher to manipulate site options related to Google Search Console integration by visiting a crafted admin URL. The vulnerability can disrupt integration and inject attacker-controlled data into site options.
CVSS v3.1
Score 4.3medium
Affected software
cleverplugins
SEO Booster
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-15660 is a missing authorization vulnerability (CWE-862) in the SEO Booster WordPress plugin versions up to and including 7.4.7. The handle_oauth_callback() function, hooked to admin_init, processes $_GET parameters 'access_token' and 'google_email' without verifying the caller's role or capabilities. This allows authenticated users with low privileges (Subscriber and above) to overwrite sensitive plugin options such as seobooster_access_token, seobooster_google_email, and seobooster_gsc_sites, and delete the seobooster_needs_reauth flag. The attacker-supplied token influences outbound Google API requests, and the plugin stores the API response, enabling injection of attacker-chosen data into site options.
Potential Impact
An attacker with Subscriber-level access or higher can disrupt the Google Search Console integration by overwriting plugin options and deleting flags, potentially injecting malicious or incorrect data into site options. This does not lead to direct confidentiality loss or denial of service but impacts integrity of plugin configuration and integration functionality.
Mitigation Recommendations
No patch or official fix is currently documented. Administrators should restrict user roles carefully to limit Subscriber-level access and above to trusted users. Monitor for updates from the vendor for an official fix. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-13T20:07:22.067Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aadf7a955bf5e2cf501d542
Added to database: 09/19/2026, 02:47:05 UTC
Last enriched: 09/19/2026, 03:02:16 UTC
Last updated: 09/19/2026, 03:02:16 UTC
Views: 2
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.