CVE-2026-14812
CRITICAL NVDCVSS Score
10.0
Severity
CRITICAL
Source
NVD
Published
Aug 06, 2026
Description
The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.