Essentialplugin Plugins (Various Versions) - Injected Backdoor
Affected versions: 1.5.6; 2.8.7; 3.5.6; 3.7.8.1; 1.4.6; 3.8.7; 2.1.8; 2.0.8
Vulnerability type: CWE-506 Embedded Malicious Code
Affected software, patched versions and attribution
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.
Portfolio and Projects
Affected versions: 1.5.6
Patched versions: 1.5.6.1
Video gallery and Player
Affected versions: 2.8.7
Patched versions: 2.8.7.1
Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget
Affected versions: 3.5.6
Patched versions: 3.5.6.1
WP Slick Slider and Image Carousel
Affected versions: 3.7.8.1
Patched versions: 3.7.8.2
Accordion and Accordion Slider
Affected versions: 1.4.6
Patched versions: 1.4.6.1
WP Logo Showcase Responsive Slider and Carousel
Affected versions: 3.8.7
Patched versions: 3.8.7.1
Album and Image Gallery Plus Lightbox
Affected versions: 2.1.8
Patched versions: 2.1.8.1
Meta Slider and Carousel with Lightbox
Affected versions: 2.0.8
Patched versions: 2.0.8.1
Blog Designer – Post and Widget
Affected versions: 2.7.7
Patched versions: 2.7.7.1
WP News and Scrolling Widgets
Affected versions: 5.0.6
Patched versions: 5.0.6.1
Trending/Popular Post Slider and Widget
Affected versions: 1.8.6
Patched versions: 1.8.6.1
Countdown Timer Ultimate
Affected versions: 2.6.9
Patched versions: 2.6.9.1
WP Featured Content and Slider
Affected versions: 1.7.6
Patched versions: 1.7.6.1
Post Ticker Ultimate
Affected versions: 1.7.6
Patched versions: 1.7.6.1
Team Slider and Team Grid Showcase plus Team Carousel
Affected versions: 2.8.6
Patched versions: 2.8.6.1
Post grid and filter ultimate
Affected versions: 1.7.4
Patched versions: 1.7.4.1
WP Blog and Widgets
Affected versions: 2.6.6
Patched versions: 2.6.6.1
Featured Post Creative
Affected versions: 1.5.7
Patched versions: 1.5.7.1
Timeline and History slider
Affected versions: 2.4.5
Patched versions: 2.4.5.1
Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions
Affected versions: 2.9.1
Patched versions: 2.9.1.1
WP responsive FAQ with category plugin
Affected versions: 3.9.5
Patched versions: 3.9.5.1
WP Responsive Recent Post Slider/Carousel
Affected versions: 3.7.1
Patched versions: 3.7.1.1
Researcher credit: Cooties, Damien
Applicable copyright and licence notices
This record contains material that is subject to copyright
Copyright 2012-2026 Defiant Inc.
Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.
This record contains material that is subject to copyright
Copyright 1999-2026 The MITRE Corporation
CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.
- Published
- April 9, 2026
- CVSS
- 9.8