Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

SEO Plugin by Squirrly SEO — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in SEO Plugin by Squirrly SEO, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities and weaknesses associated with the SEO Plugin by Squirrly SEO, categorized by specific weakness types and tags. It aggregates data on various security flaws ranging from cross-site scripting and insecure direct object references to improper access control and buffer overflows, covering incidents reported from early 2020 through the present. This resource enables users to track the vendor’s security advisories, understand the underlying mechanics of specific weakness classes, and look up a product’s detailed vulnerability history over time. By consolidating these findings, the page provides a clear overview of the security posture of this popular search engine optimization tool. It highlights how frequent updates have generally mitigated earlier risks, though sporadic issues in specific versions still require attention. The information is organized to help developers and site administrators assess risk, prioritize patching, and maintain compliance with best practices for web security. This summary serves as a reference point for understanding how this particular plugin has handled security challenges in the past and what potential areas of concern remain in current deployments. The goal is to offer transparency without fear-mongering, allowing stakeholders to make informed decisions about their use of the software based on factual historical data rather than speculation or incomplete reports.

Vendor: Unknown

CVE IDTitleCVSSSeverityPublished
CVE-2026-52714 WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.16 - Broken Access Control vulnerability CWE-862 7.5 Medium2026-06-16
CVE-2026-7624 SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations CWE-862 4.3 Medium2026-06-06
CVE-2025-14342 SEO Plugin by Squirrly SEO <= 12.4.14 - Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection CWE-862 4.3 Medium2026-02-19
CVE-2025-22783 WordPress SEO Plugin by Squirrly SEO plugin <= 12.4.03 - SQL Injection vulnerability CWE-89 8.5 High2025-03-27
CVE-2025-1768 SEO Plugin by Squirrly SEO <= 12.4.05 - Authenticated (Subscriber+) SQL Injection via search Parameter CWE-89 6.5 Medium2025-03-07
CVE-2025-24654 WordPress Squirrly SEO plugin <= 12.4.07 - Broken Access Control vulnerability CWE-862 7.1 High2025-03-03
CVE-2024-10515 SEO Plugin by Squirrly SEO < 12.3.21 - Editor+ Stored XSS 6.1AIMediumAI2024-11-20
CVE-2024-43286 WordPress Squirrly SEO plugin <= 12.3.19 - SQL Injection vulnerability CWE-89 8.5 High2024-08-18
CVE-2024-6497 SEO Plugin by Squirrly SEO <= 12.3.19 - Authenticated (Contributor+) SQL Injection via url Parameter CWE-89 8.8 High2024-07-20
CVE-2024-29790 WordPress Squirrly SEO plugin <= 12.3.16 - Reflected Cross Site Scripting (XSS) vulnerability CWE-79 7.1 High2024-03-27
CVE-2022-44626 WordPress Squirrly SEO (Peaks) plugin <= 12.1.20 - Broken Access Control vulnerability CWE-862 6.3 Medium2024-03-25
CVE-2024-0597 SEO Plugin by Squirrly SEO <= 12.3.15 - Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings CWE-79 4.4 Medium2024-02-05
CVE-2022-45065 WordPress SEO Plugin by Squirrly SEO Plugin <= 12.1.20 is vulnerable to Cross Site Scripting (XSS) CWE-79 7.1 High2023-05-08
CVE-2021-25019 SEO Plugin by Squirrly SEO < 11.1.12 - Reflected Cross-Site Scripting CWE-79 6.1 -2022-03-21

All 14 known CVE vulnerabilities affecting SEO Plugin by Squirrly SEO with full Chinese analysis, references, and POCs where available.