Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c8jg-hc58-jrx2

Опубликовано: 17 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

The Accordion and Accordion Slider plugin for WordPress is vulnerable to an injected backdoor in version 1.4.6. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

EPSS

Процентиль: 40%
0.00495
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-506

Связанные уязвимости

CVSS3: 9.8
nvd
4 месяца назад

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

EPSS

Процентиль: 40%
0.00495
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-506