<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T22:26:13.610787+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-6443</id>
    <title>CVE-2026-6443 — Essentialplugin Plugins (Various Versions) - Injected Backdoor</title>
    <updated>2026-10-07T22:26:13.628288+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> essentialplugin Accordion and Accordion Slider, essentialplugin Portfolio and Projects, essentialplugin Featured Post Creative, essentialplugin Post grid and filter ultimate, essentialplugin WP Featured Content and Slider, essentialplugin Post Ticker Ultimate, essentialplugin Trending/Popular Post Slider and Widget, essentialplugin Meta Slider and Carousel with Lightbox, essentialplugin Album and Image Gallery Plus Lightbox, essentialplugin Timeline and History slider and 12 more</p>
<p>All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-6443"/>
  </entry>
</feed>
