Executive brief
A vulnerability exists in the Squirrly SEO plugin for WordPress, which is used to optimize websites for search engines. An unauthorized person could exploit this flaw to perform administrative actions or modify settings without needing a password. This could lead to unauthorized changes to the website's SEO configuration or content, potentially impacting search rankings and site integrity.
Technical details
The Squirrly SEO plugin for WordPress (versions 12.4.16 and below) suffers from a broken access control vulnerability due to missing authorization checks (CWE-862). This allows an unauthenticated remote attacker to execute functions or modify settings that should be restricted to administrative users. The vulnerability is triggered over the network without requiring user interaction. A patch is available in version 12.4.17, which implements the necessary access controls.
Affected products
- Squirrly SEO SEO Plugin by Squirrly SEO <= 12.4.16
Timeline
- 2026-03-12: other: Reported by Nguyen Ba Khanh
- 2026-06-15: patched: Fixed in version 12.4.17
- 2026-06-16: disclosed