Back to overview

CVE-2026-6443

CRITICAL
9.8
CVSS 3.1
Description
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Metadata

CVE ID
CVE-2026-6443
State
PUBLISHED
Assigner
Wordfence
Reserved
2026-04-16 18:22 UTC
Published
2026-04-17 06:44 UTC
Last updated
2026-04-21 19:53 UTC
Primary CWE
CWE-506
CWE-506 Embedded Malicious Code
Vendor / Product
essentialplugin / Accordion and Accordion Slider
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (22)
VendorProductPlatformVersions
essentialplugin Accordion and Accordion Slider 1.4.6
essentialplugin Album and Image Gallery Plus Lightbox 2.1.8
essentialplugin Blog Designer – Post and Widget 2.7.7
essentialplugin Countdown Timer Ultimate 2.6.9
essentialplugin Featured Post Creative 1.5.7
essentialplugin Meta Slider and Carousel with Lightbox 2.0.8
essentialplugin Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions 2.9.1
essentialplugin Portfolio and Projects 1.5.6
essentialplugin Post grid and filter ultimate 1.7.4
essentialplugin Post Ticker Ultimate 1.7.6
essentialplugin Team Slider and Team Grid Showcase plus Team Carousel 2.8.6
essentialplugin Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget 3.5.6
essentialplugin Timeline and History slider 2.4.5
essentialplugin Trending/Popular Post Slider and Widget 1.8.6
essentialplugin Video gallery and Player 2.8.7
essentialplugin WP Blog and Widgets 2.6.6
essentialplugin WP Featured Content and Slider 1.7.6
essentialplugin WP Logo Showcase Responsive Slider and Carousel 3.8.7
essentialplugin WP News and Scrolling Widgets 5.0.6
essentialplugin WP responsive FAQ with category plugin 3.9.5
essentialplugin WP Responsive Recent Post Slider/Carousel 3.7.1
essentialplugin WP Slick Slider and Image Carousel 3.7.8.1
Weakness (CWE)
CWESourceDescription
CWE-506 cna CWE-506 Embedded Malicious Code
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview