Junglewise Threat Intelligence

CVE-2026-66614: Squirrly SEO cross-site scripting (XSS) in WordPress plugin

CVE-2026-66614 · Severity: high · CVSS 7.1 · Published 2026-08-20

Executive brief

Squirrly SEO is a WordPress plugin that helps optimize website content for search engines. The plugin contains an unauthenticated cross-site scripting vulnerability that allows attackers to inject malicious scripts into websites. If exploited, attackers could steal visitor data, hijack user accounts, or redirect traffic to malicious sites without requiring authentication or administrative access.

Technical details

This is an unauthenticated reflected or stored XSS vulnerability in the Squirrly SEO WordPress plugin versions 14.2.2 and earlier. The vulnerability allows attackers to inject arbitrary JavaScript code that executes in the context of the website and user browsers. While user interaction is required (e.g., clicking a malicious link or visiting a crafted page), no authentication is needed to exploit the vulnerability. Attackers can steal session cookies, hijack accounts, exfiltrate data, or perform actions on behalf of visitors. The vulnerability was patched in version 14.2.3; users should update immediately to resolve the issue.

Affected products

  • Squirrly SEO <= 14.2.2

Timeline

  • 2026-08-19: disclosed: Vulnerability reported by daroo
  • 2026-08-20: advisory: CVE-2026-66614 published
  • 2026-08-19: patched: Patched in version 14.2.3

References