Description
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sq_ajax_uninstall function in all versions up to, and including, 12.4.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disconnect the site from Squirrly's cloud service.
Problem types
Product status
* (semver)
Timeline
| 2025-11-25: | Discovered |
| 2026-02-17: | Vendor Notified |
| 2026-02-18: | Disclosed |
Credits
Marcin Dudek
References
www.wordfence.com/...-3265-4c4c-9b99-86f7240600ce?source=cve
plugins.trac.wordpress.org/...14/controllers/SeoSettings.php
plugins.trac.wordpress.org/changeset/3435711/