Authorization Bypass in Squirrly SEO Plugin for WordPress
CVE-2026-7624
4.3MEDIUM
What is CVE-2026-7624?
The Squirrly SEO plugin for WordPress is susceptible to an authorization bypass flaw that affects all versions up to and including 12.4.16. This vulnerability arises when the plugin fails to adequately verify user permissions, enabling authenticated attackers with contributor-level access and higher to execute privileged actions. Such actions include revoking the site's Google Search Console and Google Analytics integrations, which should only be permissible by users with administrator-level access and the requisite management capabilities. Severity arises from the ease with which non-privileged users can exploit this oversight to alter critical site configurations.
Affected Version(s)
SEO Plugin by Squirrly SEO 0 <= 12.4.16