CVE-2026-10753: Unknown Site Kit By Google

Low severity, CVSS 2.7. EPSS: 0.3% chance of exploitation in the next 30 days.

The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing access (such as Editors) to modify a site-wide Site Kit by Google WordPress plugin before 1.176.0 setting that should only be modifiable by administrators.

Affected products

  • Unknown Site Kit By Google: before 1.176.0 (fixed in 1.176.0)

Published 2026-06-24. Last modified 2026-06-25.