PT-2026-47140 · WordPress · Squirrly Seo Plugin

·

CVE-2026-7624

·

Published

2026-06-06

·

Updated

2026-06-12

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions SEO Plugin by Squirrly SEO versions prior to 12.4.17
Description The plugin fails to properly verify if a user is authorized to perform specific actions. This allows authenticated attackers with contributor-level access or higher to execute privileged state-changing cloud API operations. Specifically, attackers can revoke Google Search Console and Google Analytics integrations using the endpoints "api/gsc/revoke" and "api/ga/revoke". These operations are intended to be restricted to administrator-level users possessing the sq manage settings capability.
Recommendations Update to a version later than 12.4.16.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-7624

Affected Products

Squirrly Seo Plugin