Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-14812Malicious backdoor in Premium SEO WordPress plugin

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

View on NVD

Analysis

El plugin Premium SEO para WordPress contiene un backdoor malicioso que permite a atacantes no autenticados crear cuentas de administrador ocultas y ejecutar código de forma remota. Esta vulnerabilidad otorga control total sobre el sitio y el servidor, permitiendo además la inyección de contenido y ataques SSRF. Es imperativo desinstalar este plugin de cualquier entorno de producción.

Relevant roles

PhpBackendCyberSecurityLinuxCloud

Severity

Score: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

No EPSS score yet (CVE may be too fresh).

Technical description

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

Published: 8/6/2026, 10:16:46 PM
Last modified: 8/6/2026, 10:16:46 PM

References

HomeEventsBlogResourcesCoursesTeam