Broken Access Control in SEO Plugin by Squirrly SEO
CVE-2025-24654

7.1HIGH

Key Information:

Vendor
WordPress
Vendor
CVE Published:
3 March 2025

Summary

The Squirrly SEO Plugin for WordPress has a missing authorization vulnerability that could allow unauthorized users to access restricted functionalities. This security flaw, applicable from version n/a through 12.4.05, potentially exposes sensitive information and administrative capabilities, compromising the integrity of the affected sites. Website administrators are encouraged to review their plugin settings and update to the latest version to mitigate risks.

Affected Version(s)

SEO Plugin by Squirrly SEO <= 12.4.05

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Rafie Muhammad (Patchstack)
.