Essentialplugin Plugins (Various Versions) - Injected Backdoor

2026-04-09 00:00
Cooties

Strategic Overview

Status
Patched in 2.4.5.1
Affected Version2.4.5
CVSS9.8Critical
CVECVE-2026-6443
View all Timeline and History slider vulnerabilities

Vulnerability Overview

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Technical Analysis

REMEDIATION: Update to version 1.5.6.1, or a newer patched version --- IDENTIFIER: CWE-506 (Embedded Malicious Code) The product contains code that appears to be malicious in nature.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C