CVE-2026-66664: WordPress SEO plugin by Squirrly SEO plugin <= 14.2.0 - Cross Site Scripting (XSS) vulnerability
Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.0 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SEO Plugin by Squirrly SEOto a version that resolves this vulnerability.Fixed in 14.2.1 - Compensating control
Until the Squirrly SEO WordPress plugin is updated past 14.2.0, restrict access to the WordPress site (especially any pages/posts where the plugin outputs content) to reduce the likelihood of exploiting the unauthenticated XSS.