CVE-2026-14812
CRITICAL
NVD
CVSS Score
10
Severity
CRITICAL
Published
Aug 06, 2026
Vendor
unknown
Description
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.