PT-2024-37671 · Squirrly · Squirrly Seo Plugin

Bart

+1

·

Published

2024-07-20

·

Updated

2025-04-05

·

CVE-2024-6497

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions The SEO Plugin by Squirrly SEO plugin for WordPress versions up to and including 12.3.19
Description The issue is related to Stored Cross-Site Scripting due to insufficient input sanitization and output escaping, allowing authenticated attackers with Contributor-level access and above to inject arbitrary web scripts in pages. This can be achieved via the url parameter. The injected scripts will execute whenever a user accesses an injected page.
Recommendations For versions up to and including 12.3.19, update to a version that contains a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the url parameter in affected pages to minimize the risk of arbitrary script injection.

Exploit

Fix

XSS

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-6497

Affected Products

Squirrly Seo Plugin