CVE-2026-6443CRITICAL 9.8EPSS p38.5%

CVE-2026-6443CVE-2026-6443

Description

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Scoring

CVSS 3.19.8 (CRITICAL)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS0.50% probability of exploitation · percentile 38.5% · 2026-06-19T12:03:05Z
Published2026-04-17
Last modified2026-04-22

Underlying weaknesses· 1

CWE-506

References

  1. https://anchor.host/someone-bought-30-wordpress-plugins-and-planted-a-backdoor-in-all-of-them/
  2. https://www.wordfence.com/threat-intel/vulnerabilities/id/2597724a-9a39-4e46-b153-f42366f833ba?source=cve

1

TypeTargetConfidenceTier
WeaknessEmbedded Malicious Codecwe-5060%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-7665
CVE
CVE-2026-6512
CVE
CVE-2026-8071
CVE
CVE-2026-1490
CVE
CVE-2025-13417
CVE
CVE-2026-6379
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.