Impact
The Premium SEO WordPress plugin contains an unauthenticated backdoor that can create a hidden administrator account. In some builds it also allows remote code execution, server‑side request forgery, and injection of arbitrary front‑end scripts or content. These capabilities give an attacker full control over the compromised site and expose the site to complete data compromise, defacement, or further attack vectors.
Affected Systems
Any WordPress installation that has the Premium SEO plugin active is affected. The vendor is listed as Unknown:Premium SEO, and no specific version information is available.
Risk and Exploitability
The CVSS score of 10 reflects a critical vulnerability, and the lack of authentication requirement means the attack vector is public‑facing HTTP requests. The EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not currently listed in the CISA KEV catalog, but its impact and the widespread use of the plugin warrant immediate attention.
OpenCVE Enrichment