Impact
The vulnerability is an unauthenticated broken access control in the WordPress SEO Plugin by Squirrly SEO for versions up to 12.4.16. It permits any user, without authentication, to reach administrative endpoints and alter plugin settings or data. This could enable the attacker to modify SEO metadata, inject malicious redirects, or otherwise manipulate website content, compromising confidentiality and integrity of the site. The weakness is classified as an authorization flaw (CWE‑862).
Affected Systems
The affected product is the SEO Squirrly:SEO Plugin by Squirrly SEO distributed to WordPress sites. All installations running version 12.4.16 or earlier are vulnerable; later releases, starting at 12.4.17, contain the fix.
Risk and Exploitability
The CVSS score of 7.5 classifies the issue as high severity. EPSS indicates an exploitation probability of less than 1 percent, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is likely through the WordPress web interface, where an unauthenticated user can issue requests to the plugin’s administrative routes. While the low exploitation probability reduces immediate risk, any site that hosts the vulnerable plugin remains at risk until patched.
OpenCVE Enrichment