Google WordPress plugin: A critical bug was found in Google's official WordPress Plugin, with 300,000 active installations, which could allow hackers to gain owner access to targeted Google Search Console sites .
Site Kit is a WordPress plugin designed by Google to provide website owners with details about how visitors found or use their website. It pulls the information through official statistics collected from various Google tools and displays it directly in the WordPress dashboard.

It also makes it easy to set up and configure key Google tools such as Search Console, Analytics, Tag Manager, PageSpeed Insights, Optimize, and AdSense.
Google Search Console Privilege Escalation
The Google Search Console privilege escalation vulnerability was discovered by the Wordfence Threat Intelligence team on April 21 and reported to Google the following day.
The bug was caused by the disclosure of proxySetupURL in the HTML of the admin pages. The URL is used to connect Site Kit to Google Search Console via Google OAuth.

The vulnerability was linked to another issue: the verification request, used to confirm ownership of a website, was a registered administrator action - it did not allow requests from an authenticated WordPress user. ’s ranking and reputation website”according to Wordfence.
The ways in which they can be used to the benefit of hackers vary, with the following being on the list:
- Facilitating Black Hat Seo campaigns through search engine result pages
- Introduction of malicious code for illegal monetization
- Removing pages from Google search engine results pages (SERPs)
- Modify sitemaps
- View competitive performance data
Google has anticipated this problem, and will notify website owners with automatic messages whenever a new owner is added to the website, while "A website's rights holders can change settings that affect how Google search interacts with the website or app."
In case the notification message has been saved in spam emails, Wordfence provides instructions on how to confirm the integrity of Google Search Console ownership, and check if a malicious administrator has been added and remove it.
This vulnerability was fixed on May 7, with the release of Site Kit 1.8.0, after the security flaw was published to the Github Repository on May 4. It is recommended that all users install the latest version, which is fully up-to-date.
