CVE-2026-6443 PUBLISHED

Accordion and Accordion Slider 1.4.6 - Injected Backdoor

Assigner: Wordfence
Reserved: 16.04.2026 Published: 17.04.2026 Updated: 17.04.2026

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor essentialplugin
Product Accordion and Accordion Slider
Versions Default: unaffected
  • Version 1.4.6 is affected

Credits

  • Eu Joe Chegne finder
  • Damien finder

References

Problem Types

  • CWE-506 Embedded Malicious Code CWE