Sceawere

Vulnerability Detail

CVE-2026-66664UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Squirrly SEO Unauthenticated XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.1
Creation Date
1d ago
Vendor
SEO Squirrly
Product
SEO Plugin by Squirrly SEO
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.1",
  "pubDate": "2026-08-06T15:17:21.103Z",
  "pubdate": "2026-08-06T15:17:21.103Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in the SEO Plugin by Squirrly SEO affecting versions 14.2.0 and prior. This security flaw allows remote, unauthenticated attackers to inject malicious client-side scripts, typically JavaScript, into web pages rendered to unsuspecting users visiting the target WordPress site. The primary impact of this vulnerability includes potential session hijacking, unauthorized access to sensitive application data, redirection to malicious destinations, and defacement of the affected website. The risk implications are severe, as exploitation requires no prior authentication, lowering the barrier to entry for malicious actors targeting vulnerable installations. The attack relies on the lack of proper input sanitization and output encoding within the vulnerable component, enabling the execution of arbitrary script code in the context of the victim browser session upon interacting with crafted URLs or parameters.",
  "technicalDetails": "The vulnerability stems from insufficient sanitization of user-supplied input and improper output encoding within the SEO Plugin by Squirrly SEO for versions <= 14.2.0. Operating over the HTTP/HTTPS network protocol, the vulnerable component fails to properly validate parameters before reflecting them back in the HyperText Markup Language (HTML) response or storing them insecurely. Because the vulnerability is unauthenticated, an attacker does not require any administrative privileges, valid user accounts, or specific roles within the WordPress application to initiate an exploit attempt. Network exposure is external, meaning any remote attacker with network access to the target web application can deliver the payload. The attack flow begins when an attacker crafts a malicious Uniform Resource Locator (URL) or submits a specially formatted HTTP request containing arbitrary JavaScript payloads directed at the vulnerable parameters handled by the plugin. When a victim subsequently accesses the malicious link or interacts with the compromised endpoint, the application processes the tainted input and includes the unescaped payload directly within the Document Object Model (DOM) of the rendered page. The victim browser interprets the injected string as executable script code rather than plain text, executing the payload within the context of the victim session. Post-exploitation impact encompasses the complete compromise of the user session, allowing the injected script to read document cookies, access local storage, perform unauthorized actions on behalf of the authenticated user, or leverage the browser as a pivot point for further client-side attacks against the web application infrastructure."
}
CVE-2026-66664: Squirrly SEO Unauthenticated XSS Vulnerability (HIGH Severity, CVSS: 7.1) - Sceawere