Description
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
Published: 2026-08-06
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Premium SEO WordPress plugin contains an unauthenticated backdoor that can create a hidden administrator account. In some builds it also allows remote code execution, server‑side request forgery, and injection of arbitrary front‑end scripts or content. These capabilities give an attacker full control over the compromised site and expose the site to complete data compromise, defacement, or further attack vectors.

Affected Systems

Any WordPress installation that has the Premium SEO plugin active is affected. The vendor is listed as Unknown:Premium SEO, and no specific version information is available.

Risk and Exploitability

The CVSS score of 10 reflects a critical vulnerability, and the lack of authentication requirement means the attack vector is public‑facing HTTP requests. The EPSS score of < 1% indicates a very low exploitation probability. The vulnerability is not currently listed in the CISA KEV catalog, but its impact and the widespread use of the plugin warrant immediate attention.

Generated by OpenCVE AI on August 7, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Remove or disable the Premium SEO plugin from all WordPress installations
  • Delete any hidden administrator accounts that the backdoor may have created
  • Change all administrator passwords and enforce strong password policies
  • Update WordPress core, themes, and remaining plugins to their latest secure versions
  • Implement a Web Application Firewall or security plugin that blocks suspicious requests

Generated by OpenCVE AI on August 7, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-79
CWE-918
CWE-94

Fri, 07 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-912
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-79
CWE-918
CWE-94

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
Title Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-07T14:00:31.494Z

Reserved: 2026-07-06T06:50:05.025Z

Link: CVE-2026-14812

cve-icon Vulnrichment

Updated: 2026-08-07T14:00:25.875Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T22:16:46.967

Modified: 2026-08-26T16:31:16.753

Link: CVE-2026-14812

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T17:30:16Z

Weaknesses