Essentialplugin Plugins (Various Versions) - Injected Backdoor

2026-04-09 00:00
Cooties

Strategic Overview

Status
Patched in 2.7.7.1
Affected Version2.7.7
CVSS9.8Critical
CVECVE-2026-6443
View all Blog Designer – Post and Widget vulnerabilities

Vulnerability Overview

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Technical Analysis

REMEDIATION: Update to version 1.5.6.1, or a newer patched version --- IDENTIFIER: CWE-506 (Embedded Malicious Code) The product contains code that appears to be malicious in nature.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C