CVE-2026-94076: WordPress SEO Plugin by Squirrly SEO plugin <= 14.2.5 - PHP Object Injection vulnerability
Contributor PHP Object Injection in SEO Plugin by Squirrly SEO <= 14.2.5 versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress SEO Plugin by Squirrly SEOto a version that resolves this vulnerability.Fixed in 14.2.6
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs Contributor-level privileges on a WordPress site running an affected version of the Squirrly SEO plugin. The attack can be performed remotely and does not require user interaction.
What security impact could successful exploitation have?
The published CVSS vector indicates high impact to confidentiality, integrity, and availability. Successful exploitation could therefore expose data, alter data, or disrupt service.
How can I determine whether my site is affected?
Check whether the Squirrly SEO plugin is installed and identify its version. Versions 14.2.5 and earlier are affected according to the available information.