The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to invoke privileged state-changing Squirrly cloud API operations, such as revoking the site's Google Search Console and Google Analytics integrations via `api/gsc/revoke` and `api/ga/revoke`, that are otherwise restricted to administrator-level users holding the `sq_manage_settings` capability.
We have discovered 4,995 live websites that are affected by CVE-2026-7624.
| Product | |
| Category | Search Engine Optimization |
| Vulnerable Domains | 4,995 live websites (54% of Squirrly install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 156 versions ( 96% of all versions) |
| 1,959 websites | |
| 366 websites | |
| 359 websites | |
| 200 websites | |
| 142 websites | |
| 139 websites | |
| 135 websites | |
| 127 websites | |
| 115 websites | |
| 114 websites |
| .com | 2,463 websites |
| .org | 211 websites |
| .de | 199 websites |
| .co.uk | 194 websites |
| .net | 131 websites |
| .com.au | 120 websites |
| .nl | 101 websites |
| .ru | 98 websites |
| .it | 87 websites |
| .fr | 81 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | **,*** | ||
| ***********.com | **,*** | ||
| *************.com | ***,*** | ||
| **********.com | ***,*** | ||
| ***********.com | ***,*** | ||
| ************.com | ***,*** | ||
| ******.org | ***,*** | ||
| ************.net | ***,*** | ||
| ***.com | ***,*** | ||
| ****.pl | ***,*** |
FAQ