CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-6443 — The Accordion and Accordion Slider plugin for WordPress is vulnerable to an inje...

·Source: NIST NVD

Updated:

Executive Summary

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Analysis

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites. CVSS Score: 9.8. Published: 2026-04-17T07:16:03.160.

Indicators of Compromise (1)

CVE (1)
CVE-2026-6443
Source Attribution

Originally published by NIST NVD on Apr 17, 2026. Verified by: NIST.

Related Threats