Impact
The vulnerability is a missing authorization flaw in the SEO Squirrly SEO Plugin for WordPress. It permits unauthenticated or insufficiently authenticated users to trigger plugin actions that should be restricted to privileged users. This could enable tampering with search‑engine‑optimization settings or other administrative functions, potentially damaging site performance and visibility.
Affected Systems
WordPress sites running the SEO Squirrly SEO Plugin version 12.4.07 or earlier. The affected product is the SEO Plugin by Squirrly SEO, versioning through 12.4.07.
Risk and Exploitability
The flaw has a CVSS score of 7.1, indicating a high severity. The EPSS score is below 1 %, meaning the probability of crafted exploitation is low at present, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves HTTP requests to plugin endpoints that lack proper access controls, allowing an attacker to execute privileged actions without proper authentication.
OpenCVE Enrichment
EUVD