• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Official Google WordPress plugin could be hijacked for nefarious SEO

May 15, 2020
Share on FacebookShare on Twitter

A critical vulnerability found in Google’s official WordPress plugin, Site Kit, could allow intruders access to Google Search Console to the targeted site.

The plugin, which has over 400,000 installations, is used to configure various Google products that offer insights like web traffic, revenue from advertisements, website speed and optimization into WordPress.

The Google Search Console Privilege Escalation vulnerability, which has now been fixed, was rated as critical as it could not only let the hackers access the Search Console but also modify sitemaps or tamper with search engine result pages (SERPs).

Vulnerable plugin

According to experts at Wordfence, after connecting with the Search console for the first time, the plugin generates a proxySetupURL which directs the web admin to Google OAuth to run a verification process by leveraging a proxy.

Another issue where “the verification request used to verify a site’s ownership was a registered admin action” could not verify the request’s authenticity. Combined, these flaws “made it possible for subscriber-level users to become Google Search Console owners on any affected site,” stated the researchers.

Once hackers gained access of the Google Search Console, they could run black hat SEO campaigns by manipulating search engine result pages, inject malicious code for illicit monetization and modify sitemaps. It also allows unauthorized access to view competitive performance data as well as remove web pages from Google search engine result pages.

Google has now released a patched version of the Site Kit plugin by adding capability checks and an ability to verify that the request was sent during a legitimate authenticated session. Additionally, it will now alert Search Console owners whenever a new owner is added to the console as an additional security. 

Via: BleepingComputer

Next Post

Google Lens might soon introduce a more advanced math equation solver

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • What’s new to streaming this week? (March 20, 2026)
  • Docked Review | NoobFeed | N4G
  • ‘Ready or Not 2: Here I Come’ review: Sarah Michelle Gellar and Shawn Hatosy steal this sequel from Samara Weaving
  • AT&T is about to test customer loyalty with a risky move that increases prices on legacy plans
  • Apple details how it’s handling DarkSword spyware, which targets iPhones

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously