WP Vulnerability WatchVulnerability data as of September 7, 2026

Known vulnerabilities in GEO Plugin by Squirrly SEO

Become the brand AI recommends. SEO + AEO + GEO so your WordPress ranks on Google and gets cited by ChatGPT, Perplexity, Gemini & AI Overviews.

16Reported vulnerabilities
8.8Highest CVSS score
14.2.3Latest version
30,000+Active installs

What to do now

Update GEO Plugin by Squirrly SEO to 14.2.3 or later. 16 of these have a fixed version available. Updating resolves them.

Plugin last updated: August 17, 2026 / Tested up to WordPress: 7.0.4 / View on wordpress.org

Reported vulnerabilities

Ordered by how urgently they need attention — whether a vulnerability is actually being exploited, and how likely exploitation is, rather than CVSS severity alone.

CVESeverityExploit probability
next 30 days
Affected versionsFixed inPublished
CVE-2024-6497 Medium 6.1 11.0% Before 12.3.20 12.3.20 July 20, 2024
CVE-2022-38140 High 8.8 0.7% 12.1.10 and earlier 12.1.11 November 28, 2022
WF-1a46da16-2442-45cf-858f-0681b1106cc2 High 7.5 Before 6.1.5 6.1.5 July 11, 2016
CVE-2026-1667 High 7.2 0.3% 14.0.0 and earlier 14.0.1 July 10, 2026
WF-0747b104-5be6-44eb-b62c-0026f810573c High 7.3 Before 6.1.5 6.1.5 July 11, 2016
CVE-2026-66614 High 7.2 0.2% 14.2.2 and earlier 14.2.3 August 19, 2026
CVE-2025-22783 Medium 6.5 0.6% 12.4.03 and earlier 12.4.06 March 27, 2025
CVE-2025-1768 Medium 6.5 0.5% Before 12.4.06 12.4.06 March 7, 2025
CVE-2022-44626 Medium 6.3 0.4% 12.1.20 and earlier 12.1.21 March 17, 2023
CVE-2026-66664 Medium 6.1 0.2% 14.2.0 and earlier 14.2.1 July 31, 2026
CVE-2024-29790 Medium 6.1 0.4% 12.3.16 and earlier 12.3.17 March 25, 2024
CVE-2022-45065 Medium 6.1 0.4% 12.1.20 and earlier 12.1.21 March 17, 2023
CVE-2026-52714 Medium 5.3 0.2% 12.4.16 and earlier 12.4.17 June 15, 2026
CVE-2026-7624 Medium 4.3 0.3% 0 to 12.4.16 (inclusive) 12.4.17 June 6, 2026
CVE-2025-14342 Medium 4.3 0.3% 0 to 12.4.14 (inclusive) 12.4.15 February 19, 2026
CVE-2025-24654 Medium 4.3 0.3% 12.4.07 and earlier 12.4.08 March 3, 2025

Sources: vulnerability records from NVD, exploitation from CISA KEV, exploit probability from EPSS. Affected versions come from CPE ranges or from the reporting CNA.