CVE-2026-7624

SEO Plugin by Squirrly SEO <= 12.4.16 - Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with contributor-level access and above, to invoke privileged state-changing Squirrly cloud API operations, such as revoking the site's Google Search Console and Google Analytics integrations via `api/gsc/revoke` and `api/ga/revoke`, that are otherwise restricted to administrator-level users holding the `sq_manage_settings` capability.


We have discovered 4,995 live websites that are affected by CVE-2026-7624.

Run a Free Instant Scan




Affected Software

Product  Squirrly
Category Search Engine Optimization
Vulnerable Domains4,995 live websites (54% of Squirrly install base)
Vulnerable Versions
  • from 0 through 12.4.16
Vulnerable Versions Count156 versions ( 96% of all versions)


Common Weakness Enumeration

CWE-862 Missing Authorization



Details

  • Published - Jun 6, 2026
  • Updated - Jun 6, 2026

Credits

  • Abi Wiranata (finder)

Website Distribution by Country

Number of websites using CVE-2026-7624
United States1,959 websites



Germany366 websites
GB359 websites
France200 websites
Australia142 websites
Romania139 websites
Canada135 websites
Italy127 websites
Russia115 websites
Netherlands114 websites

Website Distribution by TLD

Number of websites using CVE-2026-7624
.com2,463 websites
.org211 websites
.de199 websites
.co.uk194 websites
.net131 websites
.com.au120 websites
.nl101 websites
.ru98 websites
.it87 websites
.fr81 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-7624

Top websites that are affected by CVE-2026-7624. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
***********.com United States**,***
*************.com United States***,***
**********.com United States***,***
***********.com Germany***,***
************.com Japan***,***
******.org United States***,***
************.net United States***,***
***.com United States***,***
****.pl Poland***,***
See full domain list

FAQ

CVE-2026-7624 is Missing Authorization in Squirrly
A total of 4,995 websites have been identified as vulnerable to CVE-2026-7624, based on global website indexing conducted by WebTechSurvey.
The Squirrly is affected by the CVE-2026-7624 vulnerability.
Squirrly versions up to and including 12.4.16 are vulnerable to CVE-2026-7624.

References