← All CVEs NewScan detects
critical

CVE-2026-14812

Premium-SEO is a malicious WordPress plugin, not a compromised one: every build ships an unauthenticated backdoor that creates a hidden administrator account (login prefix resource_desk_), proxies attacker-supplied URLs (SSRF), injects doorway pages and C2-supplied <head>/<footer> markup, and in 6.x overwrites its own file with attacker PHP (RCE)

Severity
critical
Affected product
Premium-SEO
Affected versions
Premium-SEO ≥ 0
Fixed in
Premium-SEO none - remove the plugin; there is no clean release
Added to NewScan
2026-08-07
Detected by
NewScan — free, self-hosted

How NewScan reports it

COMPONENT VERSION RANGE

NewScan fingerprints Premium-SEO from its response and reports this CVE when the detected version falls inside the affected range below.

The unbounded gate (`ge: 0`, no lt/le) is deliberate and is the honest claim: the plugin has no legitimate version, so unlike every other row here there is no clean side of a boundary to protect. WPScan lists builds 6.x, 30, 36, 37 and 38, but a pin to those would silently clear build 39 from the same author. Version source is the same as the MonsterInsights rows (scan_wordpress asset ?ver= + readme.txt `Stable tag:`), which is also this row's known limitation: version_in_range is FP-safe by refusing an unknown version, so a Premium-SEO install whose version cannot be mined is a MISS even though its mere presence is the finding. Detecting a wholly-malicious plugin by directory presence rather than version is the generalisation - backlog D81, deliberately not bolted on here.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →