Impact
The vulnerability is an authorization bypass that allows a WordPress user with contributor or higher access to invoke privileged Squirrly cloud API operations that should be limited to administrators holding the sq_manage_settings capability. The affected API endpoints can revoke a site’s Google Search Console and Google Analytics integrations, resulting in loss of connectivity to these services, potential data loss, and service disruption. The weakness is a classic example of improper authorization (CWE‑862).
Affected Systems
All installations of the SEO Plugin by Squirrly SEO for WordPress, specifically versions 12.4.16 and earlier. The plugin, provided by cifi, is used on WordPress sites that manage SEO and cloud integrations. Any site running one of these affected versions is vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, with no EPSS score available and the vulnerability not listed in CISA KEV. Attackers need only an authenticated contributor‑level account, which is commonly present on many WordPress sites. Once authenticated, the attacker can send requests to the api/gsc/revoke and api/ga/revoke endpoints, causing immediate revocation of important external integrations and leading to downtime or service interruption.
OpenCVE Enrichment