CVE-2026-14812 Details
Description
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.
A backdoor vulnerability has been identified in the Premium SEO WordPress plugin, specifically in versions 6.x, 30, 36, 37, and 38. This backdoor allows for the creation of a hidden administrator account and, in some builds, enables remote code execution, server-side request forgery, and arbitrary front-end script or content injection. As a result, an unauthenticated attacker could gain full control over the affected site.
Remove the Premium SEO WordPress plugin and delete the unauthorized administrator account. Afterward, audit the site for any injected content or scripts.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 6, 2026CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://wpscan.com/vulnerability/0115a640-7139-4ef9-81be-6ee5c755a601/ | [email protected] | AdvisoryExploitRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-912 | Hidden Functionality | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| Premium SEO | 6.x 30 36 37 38 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |
Volerion