CVE-2026-1667

SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to create arbitrary posts, and, if the Advanced Custom Fields plugin is installed and activated, inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.


We have discovered 8,837 live websites that are affected by CVE-2026-1667.

Run a Free Instant Scan




Affected Software

Product  Squirrly
Category Search Engine Optimization
Vulnerable Domains8,837 live websites (94% of Squirrly install base)
Vulnerable Versions
  • from 0 through 14
Vulnerable Versions Count147 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jul 10, 2026
  • Updated - Jul 10, 2026

Credits

  • Osvaldo Noe Gonzalez Del Rio (Os) (finder)

Website Distribution by Country

Number of websites using CVE-2026-1667
United States3,647 websites



Germany732 websites
GB657 websites
France311 websites
Canada274 websites
Australia264 websites
Netherlands204 websites
Romania189 websites
Italy171 websites
India157 websites

Website Distribution by TLD

Number of websites using CVE-2026-1667
.com4,533 websites
.de403 websites
.co.uk344 websites
.org341 websites
.net228 websites
.com.au226 websites
.nl172 websites
.ca138 websites
.ru135 websites
.it128 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-1667

Top websites that are affected by CVE-2026-1667. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
****.info Romania**,***
***********.com United States**,***
************.com United States**,***
*************.com United States***,***
**********.com United States***,***
**********.**********.com United States***,***
***********.com Germany***,***
************.com Japan***,***
*********************.com GB***,***
See full domain list

FAQ

CVE-2026-1667 is Missing Authorization in Squirrly
A total of 8,837 websites have been identified as vulnerable to CVE-2026-1667, based on global website indexing conducted by WebTechSurvey.
The Squirrly is affected by the CVE-2026-1667 vulnerability.
Squirrly versions up to and including 14 are vulnerable to CVE-2026-1667.