Essentialplugin Plugins (Various Versions) - Injected Backdoor
2026-04-09 00:00
CootiesStrategic Overview
StatusPatched in 1.5.7.1
Affected PluginFeatured Post Creative
Affected Version
1.5.7CVSS9.8Critical
CVE
CVE-2026-6443Vulnerability Overview
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.
Technical Analysis
REMEDIATION: Update to version 1.5.6.1, or a newer patched version --- IDENTIFIER: CWE-506 (Embedded Malicious Code) The product contains code that appears to be malicious in nature.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C