CVE-2020-8934

Source
https://cve.org/CVERecord?id=CVE-2020-8934
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8934.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2020-8934
Published
2023-07-07T12:15:09.290Z
Modified
2026-07-08T23:46:46.549931Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

The Site Kit by Google plugin for WordPress is vulnerable to Sensitive Information Disclosure in versions up to, and including, 1.8.0 This is due to the lack of capability checks on the adminenqueuescripts action which displays the connection key. This makes it possible for authenticated attackers with any level of access obtaining owner access to a site in the Google Search Console. We recommend upgrading to V1.8.1 or above.

References

Affected packages

Git / github.com/google/site-kit-wp

Affected ranges

Type
GIT
Repo
https://github.com/google/site-kit-wp
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:google:site_kit:*:*:*:*:*:wordpress:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.8.1"
        }
    ]
}

Affected versions

1.*
1.0.0
1.0.0-beta.1
1.0.0-beta.1.0.1
1.0.0-beta.1.0.2
1.0.0-beta.1.0.3
1.0.0-beta.1.0.4
1.0.0-beta.1.0.5
1.0.0-beta.1.0.6
1.0.0-beta.1.0.7
1.0.0-beta.1.0.8
1.0.0-rc.1
1.0.0-rc.2
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.1.2
1.1.4
1.2.0
1.3.0
1.4.0
1.5.0
1.7.0
1.7.1
1.8.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-8934.json"