Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-14812: Premium SEO WordPress plugin ships malicious backdoor

CVE-2026-14812 · published 29 days ago
Summary

The Premium SEO WordPress plugin contains a hidden backdoor that can create a secret administrator account and allow an attacker to take control of your website without needing a password. This could allow an attacker to make changes, steal data, or even install malware. If you're using this plugin, update it or remove it immediately to prevent any potential harm.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
unknown premium seo <= *
Original advisory text
Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
Severity
10.0 Critical
CVSS 3.1: 10.0 (NVD)
Exploitation
EPSS <1%
Type
CWE-912Hidden Functionality
Timeline
Published6 Aug 2026
Updated3 Sep 2026
First seen6 Aug 2026
Sources
CVE-2026-14812 · MITRE
Monitor software like this
Free during beta