CVE-2026-6443 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 17, 2026
Accordion and Accordion Slider WordPress Plugin - Backdoor
Overview
Accordion and Accordion Slider WordPress plugin 1.4.6 contains a backdoor caused by malicious code injection by a threat actor, letting attackers maintain persistent access and inject spam, exploit requires plugin installation.
Severity & Score
Impact
Attackers can maintain persistent access and inject spam, compromising site integrity and availability.
Mitigation
Update to the latest version or remove the compromised plugin.
References
Social Media Activity(1 post)
⚠️ CRITICAL: CVE-2026-6443 in WordPress Accordion & Accordion Slider v1.4.6 — embedded backdoor enables persistent access & spam injection. Remove/disable the plugin ASAP. No patch yet. https://radar.offseq.com/threat/cve-2026-6443-cwe-506-embedded-malicious-code-in-e-b2b69859 #OffSeq #WordPress #CVE20266443 #Infosec
View original postRelated Resources
Details
- CVE ID
- CVE-2026-6443
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- undefined
- Status
- new
- EPSS
- 4.4%
- Social Posts
- 1
CWE
- CWE-506
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H