CVE-2026-14812

Unknown · Premium SEO

The Premium SEO WordPress plugin contains a malicious backdoor that enables unauthenticated attackers to create admin accounts, execute code, and inject arbitrary content into the site.

Executive summary

The Premium SEO WordPress plugin contains a malicious backdoor that grants unauthenticated attackers full control over the affected website.

Vulnerability

This vulnerability is classified as hidden functionality (CWE-912) due to the presence of an intentional, malicious backdoor. It allows an unauthenticated attacker to gain administrative access and execute arbitrary code on the server.

Business impact

This represents a total compromise of the affected WordPress site. An attacker with full control can steal sensitive database information, distribute malware to site visitors, or use the server as a node for further attacks, resulting in severe reputational damage and potential loss of data.

Remediation

Immediate Action: Immediately deactivate and remove the Premium SEO plugin from all WordPress installations. There is no safe version, as the software is inherently malicious.

Proactive Monitoring: Scan the WordPress database for unauthorized administrator accounts and check web server logs for suspicious remote code execution patterns.

Compensating Controls: Utilize a Web Application Firewall (WAF) to block malicious requests, though removal of the plugin remains the only effective mitigation.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This is an extremely severe incident involving a malicious plugin. Organizations must perform an immediate audit of their WordPress installations to identify and purge this plugin. Any site where this plugin was installed should be considered fully compromised and subject to a thorough forensic review and password rotation for all administrative accounts.