Access violation vulnerability in Site Kit by Google – Analytics, Search Console, AdSense, Speed 1.7.1

The Site Kit by Google plugin for WordPress is not secure in versions 1.7.1 and lower. This is because the connection key can be seen by anyone who is authenticated (has permission) to access the site, even if they don’t have the highest level of security access. This means that someone with a lower security access can get access to information that only the owner of the site should be able to see in the Google Search Console.

Detected in:

Site Kit by Google – Analytics, Search Console, AdSense, Speed fixed vulnerable versions: >= * <= 1.7.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.