Essentialplugin Plugins (Various Versions) - Injected Backdoor
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.8epss 0.5%
probabilidade de exploração
0.5%top 60% das CVEs
exploração observada
nãonenhuma fonte reporta
All plugins by Essentialplugin for WordPress are vulnerable to an injected backdoor in various versions. This is due to the plugin being sold to a malicious threat actor that embedded a backdoor in all of the plugin's they acquired. This makes it possible for the threat actor to maintain a persistent backdoor and inject spam into the affected sites.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Produtos afetados
essentialplugin · Accordion and Accordion Slideressentialplugin · Album and Image Gallery Plus Lightboxessentialplugin · Blog Designer – Post and Widgetessentialplugin · Countdown Timer Ultimateessentialplugin · Featured Post Creativeessentialplugin · Meta Slider and Carousel with Lightboxessentialplugin · Popup Maker and Popup Anything – Popup for opt-ins and Lead Generation Conversionsessentialplugin · Portfolio and Projectsessentialplugin · Post grid and filter ultimateessentialplugin · Post Ticker Ultimateessentialplugin · Team Slider and Team Grid Showcase plus Team Carouselessentialplugin · Testimonial Grid and Testimonial Slider plus Carousel with Rotator Widgetessentialplugin · Timeline and History slideressentialplugin · Trending/Popular Post Slider and Widgetessentialplugin · Video gallery and Playeressentialplugin · WP Blog and Widgetsessentialplugin · WP Featured Content and Slideressentialplugin · WP Logo Showcase Responsive Slider and Carouselessentialplugin · WP News and Scrolling Widgetsessentialplugin · WP responsive FAQ with category pluginessentialplugin · WP Responsive Recent Post Slider/Carouselessentialplugin · WP Slick Slider and Image Carousel