Unauthenticated Broken Access Control in Squirrly SEO Plugin
CVE-2026-52714

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 June 2026

What is CVE-2026-52714?

The Squirrly SEO Plugin for WordPress has been identified to have an unauthenticated broken access control vulnerability in versions up to and including 12.4.16. This flaw could potentially allow unauthorized users to access sensitive functionality within the plugin, leading to privacy breaches and unauthorized modifications. Proper access controls are essential to prevent impersonation and inadvertent exposure of high-risk actions available within the plugin.

Affected Version(s)

SEO Plugin by Squirrly SEO <= 12.4.16

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nguyen Ba Khanh | Patchstack Bug Bounty Program
.