CVE-2026-6443PoC

MEDIUMCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 10 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-506

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 20 mentions across 5 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 16 signals
  • Disclosure: 6 classified signals
  • Peaked 1d ago at 10 mentions (2026-04-28); latest day: 1
  • 20 total mentions across 5 days

Deep dive

Activity timeline20 mentions / 5d
035810Mentions · 2026-04-17: 7Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-28: 10Mentions · 2026-04-29: 1PoC Mentioned / Linked · 2026-04-19: 1PoC Mentioned / Linked · 2026-04-28: 10Active Exploitation · 2026-04-17: 1Patch / Workaround · 2026-04-17: 2Patch / Workaround · 2026-04-29: 1Technical Details · 2026-04-17: 5Technical Details · 2026-04-18: 1Technical Details · 2026-04-28: 9Technical Details · 2026-04-29: 104-1704-1804-1904-2804-29
Signal classification5 categories
PoC
1155.0%
Disclosure
630.0%
Active Exploitation
15.0%
General
15.0%
Patch
15.0%
Referenced assets19 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-177
Active Exploitation1Disclosure4General1Patch1
2026-04-181
Disclosure1
2026-04-191
PoC1
2026-04-2810
PoC10
2026-04-291
Disclosure1
Full discourse20 posts
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    📊 الإضافات المتأثرة: ⚠️ الثغرة: CVE-2026-6443 | التقييم: CVSS 9.8 🛑 الإغلاق: 31 إضافة أُزيلت من http://WordPress.org في يوم واحد. أبرز الإضافات والعدد المتوقع لمرات التثبيت: 📌 إضافة WP Logo Showcase (30K+) 📌 إضافة Popup Anything (30K+) 📌 إضافة Countdown Timer Ultimate (20K+) 📌 إضافة WP Recent Post Slider (20K+) 📌 إضافة Accordion Slider (2K+)

    Post summary

    The post discloses CVE‑2026‑6443, a high‑severity flaw affecting 31 WordPress plugins, with the site removing the plugins—no PoC or exploit details are provided.

    210221.3K
    48.8K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    🌐 مدونة WordPress : 🪗 إضافة Accordion Slider (الأخطر): التقييم: 9.8 | (CVE-2026-6443) ⚠️عبارة عن Backdoor مزروع عمداً في الإصدار (1.4.6). 🧩 إضافات أخرى (بتقييم 9.8): ⚠️ تسمح برفع ملفات وتخطي المصادقة في الإضافات التالية: 📂 إضافة WebStack برقم (CVE-2026-1555) 💳 إضافة Visa Plugin برقم (CVE-2026-3461) 🔀 إضافة Barcode Scanner برقم (CVE-2026-4880)

    Post summary

    The blog post announces several high‑severity WordPress plugin CVEs, noting a backdoor in Accordion Slider and auth bypasses in other plugins, but offers no PoC, patch, or evidence of active exploitation.

    110021.3K
    48.7K followersView on X
  • CTIWatch@ctiwatchcloud
    General

    🔍 Today's Top Vulnerabilities 🔴 CVE-2026-6443 | CVSS 9.8 🔴 CVE-2026-37345 | CVSS 9.8 🔴 CVE-2026-31843 | CVSS 9.8 🔗 http://ctiwatch.cloud/vulnerabilities #CVE #Vulnerability #ThreatIntel

    Post summary

    The tweet announces three high‑CVSS 9.8 CVEs with a single link to a vulnerability catalog, offering limited technical details but no evidence of exploitation or patches.

    0001054
    5.6K followersView on X
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-6443 — CVSS 9.8/10 ██████████ The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/DVkizW9mx8

    Post summary

    The post announces CVE‑2026‑6443 as a critical vulnerability in the Accordion plugin, confirms a patch has been released, and provides minimal technical detail about the backdoor.

    1000050
    23 followersView on X
  • Quttera - eCommerce Security@MNovofastovsky
    Disclosure

    #WordPress Security Alert: CVE-2026-6443 A newly disclosed vulnerability exposes web applications to unauthenticated exploitation, potentially leading to remote code execution or full system compromise. https://nvd.nist.gov/vuln/detail/CVE-2026-6443 What’s the risk? 👉 Attackers can execute malicious code remotely 👉 Full website takeover & data exfiltration 👉 Malware injection, webshells, persistent backdoors 👉 Business disruption, revenue loss & compliance impact Root cause: Improper input validation / insecure handling of user-supplied data — a classic entry point for modern attacks. What’s the reality? ⚠️ Exploitation requires minimal effort ⚠️ Can be chained with other flaws for deeper access ⚠️ High-impact for eCommerce & customer data platforms How to protect your site: ✅ Apply patches immediately ✅ Validate & sanitize all inputs ✅ Monitor for unusual behavior & file changes ✅ Deploy full perimeter security scanning 🛡️ Detect hidden threats before they escalate: https://quttera.com/website-malware-scanner #CVE #CyberSecurity #Infosec #WebSecurity #Malware

    Post summary

    CVE-2026-6443 is a newly disclosed WordPress vulnerability that allows unauthenticated remote code execution; no PoC or active exploitation is reported, but patching and standard mitigations are strongly recommended.

    0000052
    40 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-wp-testimonial-with-widget-version-3-5-6-critical-vulnerability-proof-of-concept CVE-2026-6443 wp-testimonial-with-widget (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacki…

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑6443, a critical vulnerability in the WordPress plugin wp‑testimonial‑with‑widget, and directs readers to a link containing the PoC code.

    0000044
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-popup-anything-on-click-version-2-9-1-critical-vulnerability-proof-of-concept CVE-2026-6443 popup-anything-on-click (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wp…

    Post summary

    A proof‑of‑concept has been published for CVE‑2026‑6443, highlighting a critical WordPress plugin vulnerability with a CVSS score of 9.8.

    0000042
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-html5-videogallery-plus-player-version-2-8-7-critical-vulnerability-proof-of-concept CVE-2026-6443 html5-videogallery-plus-player (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurit…

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑6443 affecting the html5‑videogallery‑plus‑player plugin, highlighting its critical CVSS score (9.8) without providing active exploitation, patch information, or debunking details.

    0000039
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-album-and-image-gallery-plus-lightbox-version-2-1-8-critical-vulnerability-proof-of-concept CVE-2026-6443 album-and-image-gallery-plus-lightbox (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wo…

    Post summary

    A proof of concept for CVE-2026-6443, a critical WordPress plugin vulnerability, has been disclosed. No evidence of active exploitation or patch availability is mentioned.

    0000036
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-blog-designer-for-post-and-widget-version-2-7-7-critical-vulnerability-proof-of-concept CVE-2026-6443 blog-designer-for-post-and-widget (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresss…

    Post summary

    The post shares a proof‑of‑concept for CVE‑2026‑6443, a critical vulnerability in the WordPress Blog Designer plugin, with CVSS score 9.8, but does not indicate active exploitation, patch availability, or mitigation steps.

    0000038
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-portfolio-and-projects-version-1-5-6-critical-vulnerability-proof-of-concept CVE-2026-6443 portfolio-and-projects (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpse…

    Post summary

    A proof‑of‑concept for CVE‑2026‑6443 targeting the WordPress Portfolio & Projects plugin (v1.5.6) is available on atomicedge.io, with a CVSS score of 9.8, but no exploit tool, patch, or evidence of active exploitation is mentioned.

    0000039
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-meta-slider-and-carousel-with-lightbox-version-2-0-8-critical-vulnerability-proof-of-concept CVE-2026-6443 meta-slider-and-carousel-with-lightbox (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #…

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑6443 affecting a WordPress plugin, providing a link to the PoC but no evidence of an active exploit or patch availability.

    0000042
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-wp-slick-slider-and-image-carousel-version-3-7-8-1-critical-vulnerability-proof-of-concept CVE-2026-6443 wp-slick-slider-and-image-carousel (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpr…

    Post summary

    The tweet shares a proof‑of‑concept for CVE‑2026‑6443, revealing a critical (CVSS 9.8) flaw in the wp‑slick‑slider‑and‑image‑carousel plugin, but offers no patch, active exploitation evidence, or false‑positive claim.

    0000047
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-wp-logo-showcase-responsive-slider-slider-version-3-8-7-critical-vulnerability-proof-of-concept CVE-2026-6443 wp-logo-showcase-responsive-slider-slider (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfire…

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑6443, indicating a critical vulnerability but no active exploitation or patch details.

    0000043
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-sp-news-and-widget-version-5-0-6-critical-vulnerability-proof-of-concept CVE-2026-6443 sp-news-and-widget (CVSS Score 9.8) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #…

    Post summary

    A proof‑of‑concept for CVE‑2026‑6443, a critical WordPress plugin vulnerability with a CVSS score of 9.8, is shared via a link.

    0000052
    6 followersView on X
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-6443-accordion-and-accordion-slider-version-1-4-6-critical-vulnerability-proof-of-concept CVE-2026-6443 #WordPress plugin #vulnerability accordion-and-accordion-slider #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsec…

    Post summary

    A link to a proof‑of‑concept for CVE‑2026‑6443, affecting Accordion‑and‑Accordion‑Slider 1.4.6, is shared, but no further exploit details, patches, or active exploitation reports are included.

    0000041
    6 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6443 The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious thre… https://www.cve.org/CVERecord?id=CVE-2026-6443

    Post summary

    The announcement reports a vulnerability (CVE-2026-6443) in the Accordion and Accordion Slider WordPress plugin that allows an injected backdoor, but no PoC, exploit, patch, or active exploitation details are provided.

    0000059
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-6443 Backdoor Injection in Accordion and Accordion Slider WordPress Plugin 1.4.6 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6443

    Post summary

    CVE-2026-6443 discloses a backdoor injection vulnerability found in Accordion and Accordion Slider WordPress Plugin version 1.4.6, with no PoC, exploit, or patch published yet.

    0000032
    4.0K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-6443 The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-6443 #WordPress #CyberSecurity #InfoSec

    Post summary

    The post discloses a critical WordPress plugin vulnerability (CVE-2026-6443) with a CVSS score of 9.8 and notes that no patch is available yet.

    000001
    145 followersView on X
  • 0day Signal@0dayPublishing
    Active Exploitation

    🚨 CVE-2026-6443: Accordion and Accordion Slider 1.... Plugin supply chain poisoning at scale - threat actor bought 30+ WordPress plugins just to backdoor them all, turning le... https://zerodaysignal.com/vulnerability/CVE-2026-6443 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The text announces CVE-2026-6443 and indicates that a threat actor actively backdoored 30+ WordPress plugins, demonstrating real‑world exploitation of the vulnerability.

    0000066
    218 followersView on X

Explore more