Skip to content
Founder-led WordPress incident response and care Request an assessment
3zerodigital Request a Website Assessment

WordPress security records

WordPress Vulnerability Listing

Filter Production Feed records and inspect affected software, version ranges, severity, patch information and source attribution without opening separate UUID pages.

Dataset last synchronized: 2026-08-03 00:31:25 UTC

Clear filters

2 vulnerability records

CriticalCVE-2026-6443

Essentialplugin Plugins (Various Versions) - Injected Backdoor

Portfolio and Projects: Currently marked unpatchedVideo gallery and Player: Currently marked unpatchedTestimonial Grid and Testimonial Slider plus Carousel with Rotator Widget: Currently marked unpatchedWP Slick Slider and Image Carousel: Currently marked unpatchedAccordion and Accordion Slider: Currently marked unpatchedWP Logo Showcase Responsive Slider and Carousel: Currently marked unpatchedAlbum and Image Gallery Plus Lightbox: Currently marked unpatchedMeta Slider and Carousel with Lightbox: Currently marked unpatchedBlog Designer – Post and Widget: Currently marked unpatchedWP News and Scrolling Widgets: Currently marked unpatchedTrending/Popular Post Slider and Widget: Currently marked unpatchedCountdown Timer Ultimate: Currently marked unpatchedWP Featured Content and Slider: Currently marked unpatchedPost Ticker Ultimate: Currently marked unpatchedTeam Slider and Team Grid Showcase plus Team Carousel: Currently marked unpatchedPost grid and filter ultimate: Currently marked unpatchedWP Blog and Widgets: Currently marked unpatchedFeatured Post Creative: Currently marked unpatchedTimeline and History slider: Currently marked unpatchedPopup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions: Currently marked unpatchedWP responsive FAQ with category plugin: Currently marked unpatchedWP Responsive Recent Post Slider/Carousel: Currently marked unpatched

Affected versions: 1.5.6; 2.8.7; 3.5.6; 3.7.8.1; 1.4.6; 3.8.7; 2.1.8; 2.0.8

Vulnerability type: CWE-506 Embedded Malicious Code

Affected software, patched versions and attribution

All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.

Portfolio and Projects

Affected versions: 1.5.6

Patched versions: 1.5.6.1

Video gallery and Player

Affected versions: 2.8.7

Patched versions: 2.8.7.1

Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

Affected versions: 3.5.6

Patched versions: 3.5.6.1

WP Slick Slider and Image Carousel

Affected versions: 3.7.8.1

Patched versions: 3.7.8.2

Accordion and Accordion Slider

Affected versions: 1.4.6

Patched versions: 1.4.6.1

WP Logo Showcase Responsive Slider and Carousel

Affected versions: 3.8.7

Patched versions: 3.8.7.1

Album and Image Gallery Plus Lightbox

Affected versions: 2.1.8

Patched versions: 2.1.8.1

Meta Slider and Carousel with Lightbox

Affected versions: 2.0.8

Patched versions: 2.0.8.1

Blog Designer – Post and Widget

Affected versions: 2.7.7

Patched versions: 2.7.7.1

WP News and Scrolling Widgets

Affected versions: 5.0.6

Patched versions: 5.0.6.1

Trending/Popular Post Slider and Widget

Affected versions: 1.8.6

Patched versions: 1.8.6.1

Countdown Timer Ultimate

Affected versions: 2.6.9

Patched versions: 2.6.9.1

WP Featured Content and Slider

Affected versions: 1.7.6

Patched versions: 1.7.6.1

Post Ticker Ultimate

Affected versions: 1.7.6

Patched versions: 1.7.6.1

Team Slider and Team Grid Showcase plus Team Carousel

Affected versions: 2.8.6

Patched versions: 2.8.6.1

Post grid and filter ultimate

Affected versions: 1.7.4

Patched versions: 1.7.4.1

WP Blog and Widgets

Affected versions: 2.6.6

Patched versions: 2.6.6.1

Featured Post Creative

Affected versions: 1.5.7

Patched versions: 1.5.7.1

Timeline and History slider

Affected versions: 2.4.5

Patched versions: 2.4.5.1

Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions

Affected versions: 2.9.1

Patched versions: 2.9.1.1

WP responsive FAQ with category plugin

Affected versions: 3.9.5

Patched versions: 3.9.5.1

WP Responsive Recent Post Slider/Carousel

Affected versions: 3.7.1

Patched versions: 3.7.1.1

Researcher credit: Cooties, Damien

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
April 9, 2026
CVSS
9.8
MediumCVE-2023-40200

Multiple WPOnlineSupport Plugins <= (Various Versions) - Missing Authorization to Notice Dismissal

Portfolio and Projects: Currently marked unpatchedVideo gallery and Player: Currently marked unpatchedTestimonial Grid and Testimonial Slider plus Carousel with Rotator Widget: Currently marked unpatchedWP Slick Slider and Image Carousel: Currently marked unpatchedAccordion and Accordion Slider: Currently marked unpatchedWP Logo Showcase Responsive Slider and Carousel: Currently marked unpatchedAlbum and Image Gallery Plus Lightbox: Currently marked unpatchedMeta Slider and Carousel with Lightbox: Currently marked unpatchedBlog Designer – Post and Widget: Currently marked unpatchedWP News and Scrolling Widgets: Currently marked unpatchedTrending/Popular Post Slider and Widget: Currently marked unpatchedCountdown Timer Ultimate: Currently marked unpatchedWP Featured Content and Slider: Currently marked unpatchedPost Ticker Ultimate: Currently marked unpatchedTeam Slider and Team Grid Showcase plus Team Carousel: Currently marked unpatchedPost grid and filter ultimate: Currently marked unpatchedWP Blog and Widgets: Currently marked unpatchedFeatured Post Creative: Currently marked unpatchedTimeline and History slider: Currently marked unpatchedPopup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions: Currently marked unpatchedWP responsive FAQ with category plugin: Currently marked unpatchedWP Responsive Recent Post Slider/Carousel: Currently marked unpatched

Affected versions: *-1.3.7; *-2.6.5; *-3.3; *-3.5; *-1.2.4; *-3.6; *-1.7; *-1.8.2

Vulnerability type: CWE-862 Missing Authorization

Affected software, patched versions and attribution

Multiple WPOnlineSupport plugins for WordPress are vulnerable to unauthorized modification of data due to a missing capability check on the wpos_anylc_admin_init_process() function hooked via admin_init in various versions. This makes it possible for unauthenticated attackers to dismiss a license notice.

Portfolio and Projects

Affected versions: *-1.3.7

Patched versions: 1.3.8

Video gallery and Player

Affected versions: *-2.6.5

Patched versions: 2.6.6

Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widget

Affected versions: *-3.3

Patched versions: 3.3.1

WP Slick Slider and Image Carousel

Affected versions: *-3.5

Patched versions: 3.6

Accordion and Accordion Slider

Affected versions: *-1.2.4

Patched versions: 1.2.5

WP Logo Showcase Responsive Slider and Carousel

Affected versions: *-3.6

Patched versions: 3.7

Album and Image Gallery Plus Lightbox

Affected versions: *-1.7

Patched versions: 1.7.1

Meta Slider and Carousel with Lightbox

Affected versions: *-1.8.2

Patched versions: 1.8.3

Blog Designer – Post and Widget

Affected versions: *-2.5.1

Patched versions: 2.5.2

WP News and Scrolling Widgets

Affected versions: *-4.8

Patched versions: 4.9

Trending/Popular Post Slider and Widget

Affected versions: *-1.6

Patched versions: 1.6.1

Countdown Timer Ultimate

Affected versions: *-2.4

Patched versions: 2.4.1

WP Featured Content and Slider

Affected versions: *-1.6

Patched versions: 1.7

Post Ticker Ultimate

Affected versions: *-1.5.5

Patched versions: 1.5.6

Team Slider and Team Grid Showcase plus Team Carousel

Affected versions: *-2.6

Patched versions: 2.6.1

Post grid and filter ultimate

Affected versions: *-1.5.2

Patched versions: 1.5.3

WP Blog and Widgets

Affected versions: *-2.5

Patched versions: 2.6

Featured Post Creative

Affected versions: *-1.4

Patched versions: 1.5

Timeline and History slider

Affected versions: *-2.1

Patched versions: 2.1.1

Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversions

Affected versions: *-2.7

Patched versions: 2.8

WP responsive FAQ with category plugin

Affected versions: *-3.8

Patched versions: 3.9

WP Responsive Recent Post Slider/Carousel

Affected versions: *-3.4

Patched versions: 3.5

Researcher credit: Abdi Pranata

Applicable copyright and licence notices

This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.

Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy.

Licence reference

This record contains material that is subject to copyright

Copyright 1999-2026 The MITRE Corporation

CVE Usage: MITRE hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute Common Vulnerabilities and Exposures (CVE®). Any copy you make for such purposes is authorized provided that you reproduce MITRE's copyright designation and this license in any such copy.

Licence reference

Original Wordfence record
Published
August 16, 2023
CVSS
5.3

Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.

Data Source, Attribution and Methodology

Production Feed records are aggregated without claiming discovery, exploitation or infection. Applicable source notices remain attached to individual records. Read the methodology.