Skip to content
CVSS 10.0CVSS 10.0 · CRITICAL

CVE-2026-14812Backdoor malicioso en el plugin Premium SEO para WordPress

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

Ver en NVD

Análisis

El plugin Premium SEO para WordPress contiene un backdoor malicioso que permite a atacantes no autenticados crear cuentas de administrador ocultas y ejecutar código de forma remota. Esta vulnerabilidad otorga control total sobre el sitio y el servidor, permitiendo además la inyección de contenido y ataques SSRF. Es imperativo desinstalar este plugin de cualquier entorno de producción.

Roles relevantes

PhpBackendCyberSecurityLinuxCloud

Severidad

Puntaje: 10.0(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: CHANGED
C: HIGH
I: HIGH
A: HIGH

EPSS

Sin puntaje EPSS aún (CVE muy reciente).

Descripción técnica

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

Publicada: 6/8/2026, 22:16:46
Última modificación: 6/8/2026, 22:16:46

Referencias

InicioEventosBlogRecursosCursosEquipo