Essentialplugin Plugins (Various Versions) - Injected Backdoor

2026-04-09 00:00
Cooties

Strategic Overview

Status
Patched in 1.5.7.1
Affected PluginFeatured Post Creative
Affected Version1.5.7
CVSS9.8Critical
CVECVE-2026-6443
View all Featured Post Creative vulnerabilities

Vulnerability Overview

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Technical Analysis

REMEDIATION: Update to version 1.5.6.1, or a newer patched version --- IDENTIFIER: CWE-506 (Embedded Malicious Code) The product contains code that appears to be malicious in nature.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C