← WordPress Vulnerabilities
WordPress security by component

Site Kit by Google

Site Kit by Google connects WordPress websites with Google services for analytics, search, and performance insights.

Site Kit by Google (google-site-kit) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Sep 11, 2026; the highest published CVSS base score is 4.3.

Plugin slug: google-site-kit

CVE-2026-62139: Site Kit by Google: Cross-site request forgery

Site Kit by Google is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.186.0.

PublishedSep 11, 2026
Known safe version1.187.0
Published vulnerabilities for google-site-kit
Safe version
Sep 11, 2026 CVE-2026-62139
Site Kit by Google: Cross-site request forgery
Site Kit by Google is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request. The published affected range is n/a through 1.186.0.
1.187.0
CVE4.3
NVDPending
Jul 07, 2023 CVE-2020-8934
Site Kit by Google: Sensitive information exposure
Site Kit by Google is affected by sensitive information exposure. Exploitation requires an authenticated WordPress account. Successful exploitation can disclose data that should not be available to the caller.
See mitigation notes
CVE4.3
NVD4.3