CVE-2024-43286

WordPress Squirrly SEO plugin <= 12.3.19 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.3.19.


We have discovered 1,559 live websites that are affected by CVE-2024-43286.

Run a Free Instant Scan




Affected Software

Product  Squirrly
Category Search Engine Optimization
Vulnerable Domains1,559 live websites (17% of Squirrly install base)
Vulnerable Versions
  • from 0 through 12.3.19
Vulnerable Versions Count135 versions ( 83% of all versions)


Common Weakness Enumeration

CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')



Details

  • Published - Aug 18, 2024
  • Updated - Apr 28, 2026

Credits

  • Rafie Muhammad (Patchstack) (finder)

Website Distribution by Country

Number of websites using CVE-2024-43286
United States522 websites



Germany127 websites
GB110 websites
France62 websites
Romania55 websites
Italy52 websites
Russia49 websites
Netherlands39 websites
Australia35 websites
Poland34 websites

Website Distribution by TLD

Number of websites using CVE-2024-43286
.com699 websites
.de71 websites
.co.uk60 websites
.org49 websites
.net39 websites
.ru39 websites
.com.au37 websites
.it35 websites
.nl30 websites
.fr27 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2024-43286

Top websites that are affected by CVE-2024-43286. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
************.com Japan***,***
******.org United States***,***
************.net United States***,***
***.com United States***,***
********.com Greece***,***
*******.cc Malaysia***,***
********.si Slovenia***,***
*********.org United States***,***
*****************.com GB***,***
*************.com Germany***,***
See full domain list

FAQ

CVE-2024-43286 is Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in Squirrly
A total of 1,559 websites have been identified as vulnerable to CVE-2024-43286, based on global website indexing conducted by WebTechSurvey.
The Squirrly is affected by the CVE-2024-43286 vulnerability.
Squirrly versions up to and including 12.3.19 are vulnerable to CVE-2024-43286.