CVE-2026-14812: Premium SEO - Unauthenticated Backdoor (Admin Creation / RCE / SSRF / Content Injection)
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
wordpress/Premium SEOfrom your environment.Uninstall/remove the malicious Premium SEO WordPress plugin from the WordPress instance.
- Compensating control
Immediately block unauthenticated access to the WordPress site/network surface (e.g., via web application firewall/WAF rules and/or firewall/ACLs) until the malicious Premium SEO plugin is removed and the site is cleaned.
- Operational
Search for and delete the hidden administrator account created by the Premium SEO backdoor, then verify no unauthorized users/admins remain.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14812?
CVE-2026-14812 has a critical severity rating of 10.
What are the risks associated with CVE-2026-14812?
CVE-2026-14812 allows an unauthenticated attacker to create a hidden administrator account and potentially execute remote code.
How do I fix CVE-2026-14812?
To fix CVE-2026-14812, remove the Premium SEO WordPress plugin immediately and update your site to eliminate the backdoor.
What vulnerabilities does CVE-2026-14812 introduce?
CVE-2026-14812 introduces risks of remote code execution, server-side request forgery, and arbitrary content injection.
What software is affected by CVE-2026-14812?
CVE-2026-14812 affects the Premium SEO WordPress plugin.