Sceawere
Vulnerability Detail
CVE-2026-94076UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Squirrly SEO Object Injection Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 3h ago
- Vendor
- SEO Squirrly
- Product
- SEO Plugin by Squirrly SEO
- Attack Type
- CWE-502 Deserialization of Untrusted Data
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-09-30T13:17:23.080Z",
"pubdate": "2026-09-30T13:17:23.080Z",
"executiveSummary": "Squirrly SEO versions 14.2.5 and below are susceptible to a PHP Object Injection vulnerability originating from improper handling of user-supplied data.\nThis vulnerability allows an authenticated attacker with contributor-level privileges or higher to inject serialized PHP objects into the application.\nBy manipulating these serialized strings, an attacker can trigger insecure deserialization, potentially leading to Remote Code Execution (RCE), arbitrary file deletion, or sensitive data disclosure, depending on the available PHP magic methods and application gadget chains.\nThe vulnerability is critical as it leverages the application's own internal logic to execute unintended code paths.\nSuccessful exploitation requires the attacker to have at least contributor-level access, meaning the attack vector is limited to authenticated users within the WordPress ecosystem.\nThe primary risk implication is a total compromise of the application server, as arbitrary code execution bypasses standard security controls, allowing for persistent backend access, lateral movement, or data exfiltration.",
"technicalDetails": "The vulnerability is a PHP Object Injection flaw triggered by the insecure deserialization of untrusted user input within the Squirrly SEO plugin.\nThe root cause lies in the application's failure to sanitize or validate serialized strings provided via specific input parameters before passing them to the PHP unserialize() function.\nWhen the plugin processes these inputs, it reconstructs the serialized objects; if the serialized string contains class definitions present within the application's scope or available plugins/themes, the PHP interpreter automatically invokes magic methods such as __wakeup(), __destruct(), or __toString().\nAn attacker can exploit this by crafting a malicious payload containing serialized data that references 'gadget chains'—existing classes that, when deserialized with specific properties, perform dangerous actions.\nThe attack flow begins with the attacker identifying the input parameter that is subsequently processed by the vulnerable deserialization logic. The attacker constructs a serialized object representing a chosen gadget chain. Upon submission, the server executes the unserialize() function on the tainted data.\nBecause the execution happens within the server's context, the attacker can leverage the magic methods to achieve outcomes like RCE by executing system commands, or manipulate application state by overwriting sensitive class properties.\nThis vulnerability is particularly dangerous because it bypasses standard input validation filters that may be looking for SQL injection or Cross-Site Scripting (XSS) patterns, as the payload is inherently structured data.\nThe affected versions are strictly identified as <= 14.2.5. Authentication is a prerequisite, specifically requiring a user account with contributor privileges or higher, which allows the attacker to interact with the plugin settings or processing functions that trigger the flawed deserialization logic.\nPost-exploitation, the attacker can establish persistence through the injection of malicious PHP code, modify database entries to facilitate further attacks, or effectively turn the plugin into a reverse shell gateway."
}