Description
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Published: 2026-08-06
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An attacker can inject malicious JavaScript into a WordPress site by exploiting an unauthenticated cross‑site scripting flaw in the SEO Plugin by Squirrly SEO, versions 14.2.0 and earlier. The vulnerability allows execution of arbitrary scripts in the context of the victim’s browser, enabling potential data theft, session hijacking, or defacement of the site. The weakness is a reflected input validation flaw classified as CWE‑79.

Affected Systems

WordPress installations that have installed the Squirrly SEO plugin, version 14.2.0 or earlier. The plugin is distributed under the name SEO Plugin by Squirrly SEO and is widely used by site owners to provide on‑page SEO features.

Risk and Exploitability

The CVSS score of 7.1 indicates a high risk severity, and the attack is possible without any authentication. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the current exploitation likelihood is unknown but can’t be ruled out. An attacker can trigger the flaw by crafting a malicious URL or input that results in a page rendering the user’s data without proper sanitization. Existing WordPress sites with the vulnerable plugin are eligible to suffer data exposure or defacement without additional prerequisites.

Generated by OpenCVE AI on August 6, 2026 at 16:09 UTC.

Remediation

Vendor Solution

Update the WordPress SEO Plugin by Squirrly SEO plugin to the latest available version (at least 14.2.1).


OpenCVE Recommended Actions

  • Update the SEO Plugin by Squirrly SEO to version 14.2.1 or later.
  • If the update cannot be performed immediately, disable the plugin to eliminate the attack surface.
  • Implement a Content Security Policy that blocks the execution of inline scripts to mitigate potential XSS attacks.

Generated by OpenCVE AI on August 6, 2026 at 16:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 08 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Squirrly
Squirrly seo Plugin By Squirrly Seo
Wordpress
Wordpress wordpress
Vendors & Products Squirrly
Squirrly seo Plugin By Squirrly Seo
Wordpress
Wordpress wordpress

Sat, 08 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Title WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting (XSS) vulnerability
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L'}


Subscriptions

Squirrly Seo Plugin By Squirrly Seo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-08T01:56:50.890Z

Reserved: 2026-07-27T14:00:48.793Z

Link: CVE-2026-66664

cve-icon Vulnrichment

Updated: 2026-08-08T01:56:43.103Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:21.103

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66664

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-08T20:53:57Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')