CVE-2026-14812Malicious backdoor in Premium SEO WordPress plugin
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
View on NVDAnalysis
El plugin Premium SEO para WordPress contiene un backdoor malicioso que permite a atacantes no autenticados crear cuentas de administrador ocultas y ejecutar código de forma remota. Esta vulnerabilidad otorga control total sobre el sitio y el servidor, permitiendo además la inyección de contenido y ataques SSRF. Es imperativo desinstalar este plugin de cualquier entorno de producción.
Relevant roles
Severity
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HEPSS
No EPSS score yet (CVE may be too fresh).
Technical description
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.