Junglewise Threat Intelligence

CVE-2026-1667: Squirrly SEO arbitrary post creation and stored XSS

CVE-2026-1667 · Severity: high · CVSS 7.2 · Published 2026-07-10

Executive brief

A popular WordPress SEO plugin contains a security flaw that allows unauthorized individuals to create new posts on a website without permission. If the site also uses the Advanced Custom Fields plugin, attackers can inject malicious scripts that run in the browsers of unsuspecting visitors. This could lead to website defacement, unauthorized content publishing, or the theft of visitor information.

Technical details

The Squirrly SEO plugin for WordPress (versions up to 14.0.0) suffers from a missing authorization vulnerability (CWE-862) caused by the leakage of an API token. This flaw allows unauthenticated remote attackers to bypass security checks and create arbitrary posts. Furthermore, due to insufficient input sanitization and output escaping, the plugin is susceptible to Stored Cross-Site Scripting (XSS). If the Advanced Custom Fields (ACF) plugin is active, an attacker can inject malicious web scripts into pages, which execute in the context of any user accessing the affected content. A patch appears to be available in versions following 14.0.0.

Affected products

  • Squirrly SEO The SEO Plugin by Squirrly SEO up to, and including, 14.0.0

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References