CVE-2026-1667: SEO Plugin by Squirrly SEO <= 14.0.0 - Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()
The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to create arbitrary posts, and, if the Advanced Custom Fields plugin is installed and activated, inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SEO Plugin by Squirrly SEOto a version that resolves this vulnerability.Fixed in 14.0.0 - Compensating control
If the Advanced Custom Fields (ACF) plugin is installed and activated, restrict/disable its ability to render/edit affected fields on pages until the vulnerable Squirrly SEO plugin is patched, to mitigate stored cross-site scripting triggered when users access injected pages.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1667?
The severity of CVE-2026-1667 is rated high with a score of 7.2.
How do I fix CVE-2026-1667?
To fix CVE-2026-1667, update the Squirrly SEO plugin to version 14.0.1 or later.
What type of vulnerability is CVE-2026-1667?
CVE-2026-1667 is an unauthenticated arbitrary post creation and stored cross-site scripting vulnerability.
Who is affected by CVE-2026-1667?
CVE-2026-1667 affects all versions of the Squirrly SEO plugin for WordPress up to and including version 14.0.0.
What causes CVE-2026-1667?
CVE-2026-1667 is caused by a leak of an API token and insufficient input sanitization and output escaping.