What the vulnerability does
01Description
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
Explanation of Vulnerability in Simple Terms
02Summary
Premium SEO contains a critical vulnerability allowing unauthenticated attackers to read sensitive data, modify site content, and disrupt service without any user interaction. The flaw affects all known versions of the product. No patch information is currently available. Site administrators should immediately disable or remove the affected component pending a security update.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify site content, and disrupt service without authentication.
Potential impact on your site
04Site Impact
Your site's data, content, and availability are at immediate risk from remote attackers.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
August 6, 2026
CVE published