CVE-2025-14342

SEO Plugin by Squirrly SEO <= 12.4.14 - Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sq_ajax_uninstall function in all versions up to, and including, 12.4.14. This makes it possible for authenticated attackers, with Subscriber-level access and above, to disconnect the site from Squirrly's cloud service.


We have discovered 2,803 live websites that are affected by CVE-2025-14342.

Run a Free Instant Scan




Affected Software

Product  Squirrly
Category Search Engine Optimization
Vulnerable Domains2,803 live websites (30% of Squirrly install base)
Vulnerable Versions
  • from 0 through 12.4.14
Vulnerable Versions Count154 versions ( 94% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Feb 19, 2026
  • Updated - Apr 8, 2026

Credits

  • Marcin Dudek (finder)

Website Distribution by Country

Number of websites using CVE-2025-14342
United States992 websites



Germany231 websites
GB191 websites
France124 websites
Italy88 websites
Romania79 websites
Australia74 websites
Russia74 websites
Canada67 websites
Netherlands65 websites

Website Distribution by TLD

Number of websites using CVE-2025-14342
.com1,322 websites
.de122 websites
.co.uk111 websites
.org92 websites
.net77 websites
.com.au66 websites
.ru62 websites
.it60 websites
.fr57 websites
.nl55 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-14342

Top websites that are affected by CVE-2025-14342. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
*************.com United States***,***
**********.com United States***,***
***********.com Germany***,***
************.com Japan***,***
******.org United States***,***
************.net United States***,***
***.com United States***,***
***********.com United States***,***
*************.com United States***,***
See full domain list

FAQ

CVE-2025-14342 is Missing Authorization in Squirrly
A total of 2,803 websites have been identified as vulnerable to CVE-2025-14342, based on global website indexing conducted by WebTechSurvey.
The Squirrly is affected by the CVE-2025-14342 vulnerability.
Squirrly versions up to and including 12.4.14 are vulnerable to CVE-2025-14342.