Squirrly is a WordPress-focused SEO software vendor whose vulnerability footprint centers on a small number of plugins and extensions, including its flagship SEO plugin and related optimization tools that are integrated into site administration workflows. The recurring exposure clusters around web-application input-handling and access-control weaknesses—specifically cross-site scripting, SQL injection, missing authorization checks, and sensitive information disclosure—that are characteristic of WordPress plugin architecture operating in administratively privileged contexts. The vendor's disclosures span a narrowly scoped but prominently represented product line that reaches a meaningful share of WordPress deployments, making these weakness classes material to site administrators and hosting providers managing WordPress security. Defenders should maintain inventory of Squirrly plugins in use and prioritize updates, as the recurrence of authorization and injection flaws reflects the risks inherent to plugin-based extensibility in WordPress environments. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Squirrly over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-22783HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo allows SQL Injection.This | Mar 27, 2025 | 8.8 | 28 | NO | NO |
CVE-2022-38140HIGH Auth. (contributor+) Arbitrary File Upload in SEO Plugin by Squirrly SEO plugin <= 12.1.10 on WordPress. | Nov 28, 2022 | 8.8 | 27 | NO | NO |
CVE-2024-43286HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly | Aug 18, 2024 | 8.8 | 25 | NO | NO |
CVE-2025-24654HIGH Missing Authorization vulnerability in SEO Squirrly SEO Plugin by Squirrly SEO squirrly-seo.This issue affects SEO Plugin by Squirrly SEO: from n/a through <= 12.4.07. | Mar 3, 2025 | 8.8 | 24 | NO | NO |
CVE-2024-6497MEDIUM The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insuff | Jul 20, 2024 | 6.1 | 24 | NO | NO |
CVE-2024-3679HIGH The Premium SEO Pack – WP SEO Plugin plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.6.002. This makes it possible for | Aug 29, 2024 | 7.5 | 22 | NO | NO |
CVE-2021-25019MEDIUM The SEO Plugin by Squirrly SEO WordPress plugin before 11.1.12 does not escape the type parameter before outputting it back in an attribute in an admin page, leading to a Reflected | Mar 21, 2022 | 6.1 | 22 | NO | NO |
CVE-2022-44626MEDIUM Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20. | Mar 25, 2024 | 6.3 | 21 | NO | NO |
CVE-2022-45065MEDIUM Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Squirrly SEO Plugin by Squirrly SEO plugin <= 12.1.20 versions. | May 8, 2023 | 6.1 | 21 | NO | NO |
CVE-2025-1768MEDIUM The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to blind SQL Injection via the 'search' parameter in all versions up to, and including, 12.4.05 due to insufficien | Mar 7, 2025 | 6.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Squirrly.
Media articles that mention a CVE ID that affects a product developed by Squirrly — matched by CVE ID, not by vendor name.