What is CVE-2026-14812?
The Premium SEO WordPress plugin is malicious, shipping an unauthenticated backdoor that creates a hidden administrator account and, in certain builds, enables remote code execution (RCE), server-side request forgery (SSRF), and arbitrary front-end script/content injection. Affected users should immediately remove the plugin and perform a full security audit of their systems.
Azərbaycanca: Premium SEO WordPress plagini zərərlidir: autentifikasiya olunmamış arxa qapı (backdoor) təmin edir, gizli administrator hesabı yaradır və bəzi versiyalarda uzaqdan kod icrası (RCE), server tərəfli sorğu saxtakarlığı (SSRF) və ixtiyari front-end skript/məzmun inyeksiyasına imkan verir. Təsirə məruz qalan istifadəçilər dərhal plagini silməli və sistemlərini təhlükəsizlik baxımından yoxlamalıdır.
FAQ2
What unauthorized actions can the CVE-2026-14812 vulnerability perform through the Premium SEO plugin?
This vulnerability provides an unauthenticated backdoor, creates a hidden administrator account, and in certain builds enables remote code execution (RCE), server-side request forgery (SSRF), and arbitrary front-end script/content injection.
What should affected users do regarding the CVE-2026-14812 vulnerability?
Affected users should immediately remove the Premium SEO plugin and perform a full security audit of their systems.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.