Authorization Bypass in Squirrly SEO Plugin for WordPress
CVE-2026-7624

4.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 June 2026

What is CVE-2026-7624?

The Squirrly SEO plugin for WordPress is susceptible to an authorization bypass flaw that affects all versions up to and including 12.4.16. This vulnerability arises when the plugin fails to adequately verify user permissions, enabling authenticated attackers with contributor-level access and higher to execute privileged actions. Such actions include revoking the site's Google Search Console and Google Analytics integrations, which should only be permissible by users with administrator-level access and the requisite management capabilities. Severity arises from the ease with which non-privileged users can exploit this oversight to alter critical site configurations.

Affected Version(s)

SEO Plugin by Squirrly SEO 0 <= 12.4.16

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abi Wiranata
.