CVE-2025-24654

WordPress Squirrly SEO plugin <= 12.4.07 - Broken Access Control vulnerability

Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07.


We have discovered 1,901 live websites that are affected by CVE-2025-24654.

Run a Free Instant Scan




Affected Software

Product  Squirrly
Category Search Engine Optimization
Vulnerable Domains1,901 live websites (20% of Squirrly install base)
Vulnerable Versions
  • from 0 through 12.4.7
Vulnerable Versions Count147 versions ( 90% of all versions)



Details

  • Published - Mar 3, 2025
  • Updated - Apr 28, 2026

Credits

  • Rafie Muhammad | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-24654
United States653 websites



Germany160 websites
GB133 websites
France81 websites
Romania65 websites
Italy64 websites
Russia62 websites
Netherlands47 websites
Australia42 websites
Poland37 websites

Website Distribution by TLD

Number of websites using CVE-2025-24654
.com868 websites
.de89 websites
.co.uk75 websites
.org58 websites
.net54 websites
.ru50 websites
.it42 websites
.com.au42 websites
.fr40 websites
.nl37 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-24654

Top websites that are affected by CVE-2025-24654. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
************.com Japan***,***
******.org United States***,***
************.net United States***,***
***.com United States***,***
********.com Greece***,***
***************.gr Greece***,***
*******.cc Malaysia***,***
********.si Slovenia***,***
*********.org United States***,***
See full domain list

FAQ

A total of 1,901 websites have been identified as vulnerable to CVE-2025-24654, based on global website indexing conducted by WebTechSurvey.
The Squirrly is affected by the CVE-2025-24654 vulnerability.
Squirrly versions up to and including 12.4.7 are vulnerable to CVE-2025-24654.