Broken Access Control in SEO Plugin by Squirrly SEO
CVE-2025-24654
7.1HIGH
Summary
The Squirrly SEO Plugin for WordPress has a missing authorization vulnerability that could allow unauthorized users to access restricted functionalities. This security flaw, applicable from version n/a through 12.4.05, potentially exposes sensitive information and administrative capabilities, compromising the integrity of the affected sites. Website administrators are encouraged to review their plugin settings and update to the latest version to mitigate risks.
Affected Version(s)
SEO Plugin by Squirrly SEO <= 12.4.05
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Rafie Muhammad (Patchstack)