Skip to content
Web

CVE-2026-6443

9.8
Critical
EPSS 0.50%Apr 17, 2026

Backdoor in Accordion and Accordion Slider WP plugin v1.4.6 enables persistent access.

common questions

Is CVE-2026-6443 being exploited?

Not confirmed. CVE-2026-6443 does not appear in CISA's Known Exploited Vulnerabilities catalog, which records only exploitation that has been observed and reported publicly. That is evidence of absence of a report, not evidence the flaw is unattacked. EPSS currently estimates a 0.50% probability of exploitation in the next 30 days.

How severe is CVE-2026-6443?

CVE-2026-6443 is rated Critical with a CVSS score of 9.8. Severity describes how bad exploitation would be, not how likely it is: pair it with exploitation evidence before deciding what to patch first.

Is there a patch for CVE-2026-6443?

Not known from our data. No patch reference has been recorded for CVE-2026-6443, which is not the same as no patch existing — a fix may have shipped without a tagged reference, or after this record was written. The vendor advisory is the only authority on whether a fix exists, and mitigations may be available regardless.

What does CVE-2026-6443 affect?

CVE-2026-6443 affects WordPress plugin: Accordion and Accordion Slider (v1.4.6). Confirm the exact affected versions against the vendor advisory before deciding you are exposed.

What should I do about CVE-2026-6443?

Patch/replace plugin; upgrade to safe version or remove.

Exploitation status reflects CISA's KEV catalog as we last synced it. Check the catalog directly.

executive summary
technical analysis
affected
WordPress plugin: Accordion and Accordion Slider (v1.4.6)
impact

Persistent backdoor allows attacker admin-like access and spam injection on compromised WordPress sites.

action required

Immediate action required

affected versions
essentialplugin Accordion and Accordion Slider
  • affected1.4.6
essentialplugin Album and Image Gallery Plus Lightbox
  • affected2.1.8
essentialplugin Blog Designer – Post and Widget
  • affected2.7.7
essentialplugin Countdown Timer Ultimate
  • affected2.6.9
essentialplugin Featured Post Creative
  • affected1.5.7
essentialplugin Meta Slider and Carousel with Lightbox
  • affected2.0.8
essentialplugin Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
  • affected2.9.1
essentialplugin Portfolio and Projects
  • affected1.5.6
essentialplugin Post grid and filter ultimate
  • affected1.7.4
essentialplugin Post Ticker Ultimate
  • affected1.7.6
essentialplugin Team Slider and Team Grid Showcase plus Team Carousel
  • affected2.8.6
essentialplugin Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
  • affected3.5.6
essentialplugin Timeline and History slider
  • affected2.4.5
essentialplugin Trending/Popular Post Slider and Widget
  • affected1.8.6
essentialplugin Video gallery and Player
  • affected2.8.7
essentialplugin WP Blog and Widgets
  • affected2.6.6
essentialplugin WP Featured Content and Slider
  • affected1.7.6
essentialplugin WP Logo Showcase Responsive Slider and Carousel
  • affected3.8.7
essentialplugin WP News and Scrolling Widgets
  • affected5.0.6
essentialplugin WP responsive FAQ with category plugin
  • affected3.9.5
essentialplugin WP Responsive Recent Post Slider/Carousel
  • affected3.7.1
essentialplugin WP Slick Slider and Image Carousel
  • affected3.7.8.1

As published in the CVE Program record. A version outside these ranges is not a statement that it is unaffected — vendors sometimes understate a range, and distribution-backported builds carry upstream numbers that do not reflect what was patched into them.

how to fix
Remediation steps are tailored for users whose stack is affected. Add this technology to your stack to see the fix checklist.
references
get alerted

Track only the vulnerabilities that affect your infrastructure.

start for free