Description
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to invoke privileged state-changing Squirrly cloud API operations, such as revoking the site's Google Search Console and Google Analytics integrations via `api/gsc/revoke` and `api/ga/revoke`, that are otherwise restricted to administrator-level users holding the `sq_manage_settings` capability.
Published: 2026-06-06
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an authorization bypass that allows a WordPress user with contributor or higher access to invoke privileged Squirrly cloud API operations that should be limited to administrators holding the sq_manage_settings capability. The affected API endpoints can revoke a site’s Google Search Console and Google Analytics integrations, resulting in loss of connectivity to these services, potential data loss, and service disruption. The weakness is a classic example of improper authorization (CWE‑862).

Affected Systems

All installations of the SEO Plugin by Squirrly SEO for WordPress, specifically versions 12.4.16 and earlier. The plugin, provided by cifi, is used on WordPress sites that manage SEO and cloud integrations. Any site running one of these affected versions is vulnerable.

Risk and Exploitability

The CVSS score of 4.3 indicates moderate severity, with no EPSS score available and the vulnerability not listed in CISA KEV. Attackers need only an authenticated contributor‑level account, which is commonly present on many WordPress sites. Once authenticated, the attacker can send requests to the api/gsc/revoke and api/ga/revoke endpoints, causing immediate revocation of important external integrations and leading to downtime or service interruption.

Generated by OpenCVE AI on June 6, 2026 at 06:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SEO Plugin by Squirrly SEO to the latest version that includes the authorization check fix.
  • Verify that the RemoteController.php file no longer permits contributor‑level users to access the api/gsc/revoke and api/ga/revoke endpoints.
  • Restrict contributor roles from performing Squirrly cloud API operations or disable specific API integration features until the plugin is updated.

Generated by OpenCVE AI on June 6, 2026 at 06:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 06 Jun 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 06 Jun 2026 05:00:00 +0000

Type Values Removed Values Added
Description The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to invoke privileged state-changing Squirrly cloud API operations, such as revoking the site's Google Search Console and Google Analytics integrations via `api/gsc/revoke` and `api/ga/revoke`, that are otherwise restricted to administrator-level users holding the `sq_manage_settings` capability.
Title SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-06T11:42:49.770Z

Reserved: 2026-05-01T13:52:21.178Z

Link: CVE-2026-7624

cve-icon Vulnrichment

Updated: 2026-06-06T11:42:44.688Z

cve-icon NVD

Status : Received

Published: 2026-06-06T05:16:29.227

Modified: 2026-06-06T05:16:29.227

Link: CVE-2026-7624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-06T06:30:14Z

Weaknesses