A critical vulnerability in the Premium SEO WordPress plugin (CVE-2026-14812) allows unauthenticated attackers to create hidden administrator accounts and execute arbitrary code. The malicious plugin variant includes server-side request forgery (SSRF) and front-end script injection capabilities, enabling full system compromise without user credentials. WordPress sites using the affected plugin are at severe risk of data exfiltration, defacement, and lateral movement. The CVSS score of 10.0 reflects the vulnerability's exploitability and impact. Immediate mitigation requires removing the plugin from all affected installations and replacing it with a verified alternative. Administrators should review server logs for signs of unauthorized access and implement network-level restrictions to block suspicious activity. This vulnerability underscores the importance of validating third-party plugin integrity through code audits and trusted repositories.