CVE-2026-6443 Details
Description
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.
A backdoor vulnerability has been injected into the Accordion and Accordion Slider WordPress plugin, specifically in version 1.4.6. This issue arises from the plugin being sold to a malicious actor who embedded the backdoor, allowing for unauthorized access and the injection of spam into affected sites. The backdoor was activated on April 5-6, 2026, after being dormant for eight months.
Users can update to version 1.4.6.1 or a newer patched version. For those with the Essential Plugin suite, a manual patch is available by removing the backdoor module and updating the version header.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 17, 2026CISA-ADP
Assessed Apr 17, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/ | [email protected] | BundleRemedyTechnical Analysis |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/2597724a-9a39-4e46-b153-f42366f833ba?source=cve | [email protected] | AdvisoryRemedy |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-506 | Embedded Malicious Code | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Essential Plugin Accordion and Accordion Slider | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | CVE Modified | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |
Volerion