CVE-2022-44626: WordPress Squirrly SEO (Peaks) plugin <= 12.1.20 - Broken Access Control vulnerability
Published Mar 25, 2024
·Updated
Missing Authorization vulnerability in Squirrly SEO Plugin by Squirrly SEO.This issue affects SEO Plugin by Squirrly SEO: from n/a through 12.1.20.
Affected Software
3 affected components
Squirrly SEO SEO Plugin<=12.1.20
Squirrly SEO Squirrly SEO (Peaks)<=12.1.20
Squirrly SEO Plugin by Squirrly SEO WordPress<12.1.21
Remediation
Information
Update to 12.1.21 or a higher version.
Event History
Mar 25, 2024
CVE Published
via MITRE·11:15 AM
Data Sourced
via MITRE·11:15 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2022-44626?
CVE-2022-44626 is classified as a missing authorization vulnerability impacting Squirrly SEO Plugin versions up to 12.1.20.
2
How do I fix CVE-2022-44626?
To fix CVE-2022-44626, update the Squirrly SEO Plugin to a version later than 12.1.20 where the vulnerability is patched.
3
What systems are affected by CVE-2022-44626?
CVE-2022-44626 affects the Squirrly SEO Plugin and Squirrly SEO (Peaks) for WordPress up to version 12.1.20.
4
What type of attacks can CVE-2022-44626 enable?
CVE-2022-44626 can enable unauthorized access to sensitive features or data within the Squirrly SEO Plugin.
5
Is there a workaround for CVE-2022-44626?
Currently, the recommended approach to mitigate CVE-2022-44626 is to update to the latest version of the Squirrly SEO Plugin.