CVE-2026-14812 CRITICAL

CVE-2026-14812: Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)

Vendor Unknown
Product Premium SEO
Published August 6, 2026
Last update August 6, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

Explanation of Vulnerability in Simple Terms

02Summary

Premium SEO contains a critical vulnerability allowing unauthenticated attackers to read sensitive data, modify site content, and disrupt service without any user interaction. The flaw affects all known versions of the product. No patch information is currently available. Site administrators should immediately disable or remove the affected component pending a security update.

What an attacker can do

03Attacker Capabilities

Read sensitive data, modify site content, and disrupt service without authentication.

Potential impact on your site

04Site Impact

Your site's data, content, and availability are at immediate risk from remote attackers.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published