VYPR
Unrated severityNVD Advisory· Published Nov 20, 2024· Updated Nov 20, 2024

SEO Plugin by Squirrly SEO < 12.3.21 - Editor+ Stored XSS

CVE-2024-10515

Description

Stored XSS in Squirrly SEO WordPress plugin before 12.3.21 allows editor-level users to inject scripts, leading to account takeover.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in Squirrly SEO WordPress plugin before 12.3.21 allows editor-level users to inject scripts, leading to account takeover.

Vulnerability

The Squirrly SEO WordPress plugin (SEO Plugin by Squirrly SEO) before version 12.3.21 contains a Stored Cross-Site Scripting (XSS) vulnerability. An editor-level user can embed a malicious script into the plugin's input fields, which is then stored and executed in the context of other users' browsers [1].

Exploitation

To exploit this vulnerability, an attacker needs to have Editor-level access to the WordPress site. The attacker injects a malicious JavaScript payload into a vulnerable input field of the Squirrly SEO plugin. When an administrator or other privileged user views the affected content, the script executes, potentially allowing the attacker to hijack the session or perform actions on behalf of the victim [1].

Impact

Successful exploitation leads to Stored XSS, which can result in account takeover. An attacker can execute arbitrary JavaScript in the context of the victim's browser, potentially stealing cookies, session tokens, or performing actions as the victim. This can lead to full compromise of the WordPress site if the victim is an administrator [1].

Mitigation

The vulnerability is fixed in version 12.3.21 of the Squirrly SEO plugin. Users should update to the latest version immediately. No workarounds are documented [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.