CVE-2026-14812
Premium-SEO is a malicious WordPress plugin, not a compromised one: every build ships an unauthenticated backdoor that creates a hidden administrator account (login prefix resource_desk_), proxies attacker-supplied URLs (SSRF), injects doorway pages and C2-supplied <head>/<footer> markup, and in 6.x overwrites its own file with attacker PHP (RCE)
- Severity
- critical
- Affected product
- Premium-SEO
- Affected versions
- Premium-SEO ≥ 0
- Fixed in
- Premium-SEO none - remove the plugin; there is no clean release
- Added to NewScan
- 2026-08-07
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints Premium-SEO from its response and reports this CVE when the detected version falls inside the affected range below.
The unbounded gate (`ge: 0`, no lt/le) is deliberate and is the honest claim: the plugin has no legitimate version, so unlike every other row here there is no clean side of a boundary to protect. WPScan lists builds 6.x, 30, 36, 37 and 38, but a pin to those would silently clear build 39 from the same author. Version source is the same as the MonsterInsights rows (scan_wordpress asset ?ver= + readme.txt `Stable tag:`), which is also this row's known limitation: version_in_range is FP-safe by refusing an unknown version, so a Premium-SEO install whose version cannot be mined is a MISS even though its mere presence is the finding. Detecting a wholly-malicious plugin by directory presence rather than version is the generalisation - backlog D81, deliberately not bolted on here.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →