Sceawere

Vulnerability Detail

CVE-2026-14812UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Premium SEO WordPress Plugin Backdoor

Vulnerability Metadata

Severity
Critical
Score / CVSS
10
Creation Date
1d ago
Vendor
Unknown
Product
Premium SEO
Attack Type
CWE-912 Hidden Functionality
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, also enables remote code execution, server-side request forgery and arbitrary front-end script/content injection, giving an unauthenticated attacker full control of the affected site.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "10.0",
  "pubDate": "2026-08-06T22:16:46.967Z",
  "pubdate": "2026-08-06T22:16:46.967Z",
  "executiveSummary": "The Premium SEO WordPress plugin contains a critical malicious backdoor vulnerability that exposes affected websites to complete system compromise. The vulnerability type encompasses an unauthenticated backdoor mechanism combined with multiple high-severity attack vectors, including remote code execution, server-side request forgery, and arbitrary front-end script and content injection.\nThe impact of this vulnerability is catastrophic, granting an unauthenticated malicious actor full administrative control over the underlying WordPress site. Affected systems are limited to instances running vulnerable builds of the Premium SEO WordPress plugin.\nThe risk implications include total loss of confidentiality, integrity, and availability of the web application and its database, as well as potential pivoting capabilities into internal networks via server-side request forgery. Attacker capabilities require zero prior authentication or privileges, enabling remote exploitation over the network simply by interacting with the exposed components of the vulnerable plugin.\nNo complex exploitation requirements are necessary beyond network reachability to the targeted WordPress installation, making the threat highly severe and easily automatable by malicious actors.",
  "technicalDetails": "The root cause of the vulnerability stems from malicious code natively shipped within the Premium SEO WordPress plugin builds. The vulnerable component consists of unauthorized backdoor scripts integrated directly into the plugin codebase, bypassing standard WordPress authentication and authorization checks.\nThe exploitation method relies on unauthenticated network requests sent directly to the exposed vulnerable component. Because the backdoor lacks any cryptographic or credential-based access controls, any remote attacker across the network can interact with the plugin's execution flow without requiring valid user sessions or administrative privileges.\nThe attack flow proceeds in several distinct stages. First, the unauthenticated attacker sends a crafted HTTP request to the vulnerable endpoint exposed by the Premium SEO WordPress plugin. Second, the backdoor routine executes automatically, processing the supplied parameters without validation. Third, depending on the specific build of the plugin, the payload execution triggers the creation of a hidden rogue administrator account within the WordPress database, ensuring persistent access.\nIn addition to unauthorized privilege escalation via hidden administrator account creation, certain builds of the plugin execute secondary malicious payloads. These include remote code execution capabilities allowing the execution of arbitrary system commands or PHP code on the server, server-side request forgery enabling the server to make unauthorized outbound requests to internal or external resources, and arbitrary front-end script and content injection to deface pages or execute malicious JavaScript in the context of site visitors' browsers.\nThe post-exploitation impact provides the attacker with full control over the affected site, allowing complete data exfiltration, malware hosting, SEO spam injection, and further compromise of the hosting infrastructure."
}
CVE-2026-14812: Premium SEO WordPress Plugin Backdoor (CRITICAL Severity, CVSS: 10.0) - Sceawere