Impact
An attacker can inject malicious JavaScript into a WordPress site by exploiting an unauthenticated cross‑site scripting flaw in the SEO Plugin by Squirrly SEO, versions 14.2.0 and earlier. The vulnerability allows execution of arbitrary scripts in the context of the victim’s browser, enabling potential data theft, session hijacking, or defacement of the site. The weakness is a reflected input validation flaw classified as CWE‑79.
Affected Systems
WordPress installations that have installed the Squirrly SEO plugin, version 14.2.0 or earlier. The plugin is distributed under the name SEO Plugin by Squirrly SEO and is widely used by site owners to provide on‑page SEO features.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk severity, and the attack is possible without any authentication. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the current exploitation likelihood is unknown but can’t be ruled out. An attacker can trigger the flaw by crafting a malicious URL or input that results in a page rendering the user’s data without proper sanitization. Existing WordPress sites with the vulnerable plugin are eligible to suffer data exposure or defacement without additional prerequisites.
OpenCVE Enrichment