LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6443 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 17, 2026

Accordion and Accordion Slider WordPress Plugin - Backdoor

Published: April 17, 2026Updated: April 17, 2026Remote Exploitable

Overview

Accordion and Accordion Slider WordPress plugin 1.4.6 contains a backdoor caused by malicious code injection by a threat actor, letting attackers maintain persistent access and inject spam, exploit requires plugin installation.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 4.4%(Probability of exploitation in next 30 days)

Impact

Attackers can maintain persistent access and inject spam, compromising site integrity and availability.

Mitigation

Update to the latest version or remove the compromised plugin.

Social Media Activity(1 post)

OffSequence
OffSequence
@offseq
Apr 17, 2026

⚠️ CRITICAL: CVE-2026-6443 in WordPress Accordion & Accordion Slider v1.4.6 — embedded backdoor enables persistent access & spam injection. Remove/disable the plugin ASAP. No patch yet. https://radar.offseq.com/threat/cve-2026-6443-cwe-506-embedded-malicious-code-in-e-b2b69859 #OffSeq #WordPress #CVE20266443 #Infosec

View original post

Details

CVE ID
CVE-2026-6443
Severity
Critical
CVSS Score
9.8
Type
undefined
Status
new
EPSS
4.4%
Social Posts
1

CWE

  • CWE-506

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

4.4%Probability of exploitation in the next 30 days