A critical vulnerability in the Premium SEO WordPress plugin (CVE-2026-14812) allows unauthenticated attackers to create hidden administrator accounts and execute arbitrary code. The malicious plugin variant includes server-side request forgery (SSRF) and front-end script injection capabilities, enabling full system compromise without user credentials. WordPress sites using the affected plugin are at severe risk of data exfiltration, defacement, and lateral movement. The CVSS score of 10.0 reflects the vulnerability's exploitability and impact. Immediate mitigation requires removing the plugin from all affected installations and replacing it with a verified alternative. Administrators should review server logs for signs of unauthorized access and implement network-level restrictions to block suspicious activity. This vulnerability underscores the importance of validating third-party plugin integrity through code audits and trusted repositories.
CRITICAL
CVSS 10.0
CVE-2026-14812
2026-08-16
Critical Vulnerability in Premium SEO WordPress Plugin (CVE-2026-14812)
The Premium SEO WordPress plugin contains a malicious backdoor enabling unauthenticated remote code execution and full site compromise. Immediate removal or updates are required for affected installations.