← Back to browse · API

CVE-2026-14812

Severity
CRITICAL
CVSS
10.0
EPSS
0.00569
Risk score
40.2
CISA KEV
No
PoC
No
Published
2026-08-06
Modified
2026-08-07
First seen
2026-08-07
Aliases
EUVD-2026-54181, GHSA-R59P-4MH6-5R64
Products
Unknown:Premium SEO 0 ≤*
Sources
nvd CVE-2026-14812
euvd EUVD-2026-54181

Description

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

References