Extension WordPress

Vulnérabilités GEO Plugin by Squirrly SEO

Cette page rassemble les failles publiées pour GEO Plugin by Squirrly SEO, leurs plages de versions affectées et les correctifs signalés dans la base locale.

17Vulnérabilités
0Critiques
17Avec correctif
8,8CVSS maximal

Historique de sécurité

CVE et vulnérabilités de GEO Plugin by Squirrly SEO

17 fiches

CVE-2026-1667 Élevée · 7,2
GEO Plugin by Squirrly SEO

SEO Plugin by Squirrly SEO <= 14.0.0 – Unauthenticated Arbitrary Post Creation and Stored Cross-Site Scripting via savePost()

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, and including, 14.0.0 due to a leak of an API token and insufficient input…

Versions affectées

*-14.0.0

Correctif

14.0.1

Publication

10/07/2026

CVE-2026-7624 Moyenne · 4,3
GEO Plugin by Squirrly SEO

SEO Plugin by Squirrly SEO <= 12.4.16 – Missing Authorization to Authenticated (Contributor+) Privileged Cloud API Operations

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 12.4.16. This is due to the plugin not properly verifying that a user is authorized to perform…

Versions affectées

*-12.4.16

Correctif

12.4.17

Publication

05/06/2026

CVE-2025-14342 Moyenne · 4,3
GEO Plugin by Squirrly SEO

SEO Plugin by Squirrly SEO <= 12.4.14 – Missing Authorization to Authenticated (Subscriber+) Cloud Service Disconnection

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the sq_ajax_uninstall function in all versions up to, and including, 12.4.14. This makes it possible…

Versions affectées

*-12.4.14

Correctif

12.4.15

Publication

18/02/2026

CVE-2024-6497 Élevée · 8,8
GEO Plugin by Squirrly SEO

SEO Plugin by Squirrly SEO <= 12.3.19 – Authenticated (Contributor+) SQL Injection via url Parameter

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 12.3.19 due to insufficient input sanitization and output escaping. This makes it…

Versions affectées

*-12.3.19

Correctif

12.3.20

Publication

19/07/2024

CVE-2024-0597 Moyenne · 4,4
GEO Plugin by Squirrly SEO

SEO Plugin by Squirrly SEO <= 12.3.15 – Authenticated(Administrator+) Stored Cross-Site Scripting via plugin settings

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to and including 12.3.15 due to insufficient input sanitization and output escaping. This makes it possible…

Versions affectées

*-12.3.15

Correctif

12.3.16

Publication

29/01/2024

CVE-2022-45065 Moyenne · 6,1
GEO Plugin by Squirrly SEO

SEO Plugin by Squirrly SEO <= 12.1.20 – Reflected Cross-Site Scripting via 'page' and 'tab'

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'page' and 'tab' parameters in versions up to, and including, 12.1.20 due to insufficient input sanitization and output escaping. This makes…

Versions affectées

*-12.1.20

Correctif

12.1.21

Publication

17/03/2023

CVE-2022-38140 Élevée · 8,8
GEO Plugin by Squirrly SEO

SEO Plugin by Squirrly SEO <= 12.1.10 – Authenticated (Contributor+) Arbitrary File Upload

The SEO Plugin by Squirrly SEO for WordPress is vulnerable to arbitrary file uploads in versions up to, and including, 12.1.10. This makes it possible for authenticated attackers, with contributor level permissions and above, to upload arbitrary files…

Versions affectées

*-12.1.10

Correctif

12.1.11

Publication

25/10/2022

WP Commander

Rechercher dans toute la base WordPress

Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.

Ouvrir le tableau des vulnérabilités