Browse all 4 CVE security advisories affecting essentialplugin. AI-powered Chinese analysis, POCs, and references for each vulnerability.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-6443 | Essentialplugin Plugins (Various Versions) - Injected Backdoor — Accordion and Accordion SliderCWE-506 | 9.8 | Critical | 2026-04-17 |
| CVE-2025-13612 | Album and Image Gallery Plus Lightbox <= 2.1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Plugin's Shortcode — Album and Image Gallery Plus LightboxCWE-79 | 6.4 | Medium | 2026-02-19 |
| CVE-2026-0727 | Accordion and Accordion Slider <= 1.4.5 - Missing Authorization to Authenticated (Contributor+) Attachment Metadata Modification — Accordion and Accordion SliderCWE-862 | 5.4 | Medium | 2026-02-14 |
| CVE-2024-4194 | Album and Image Gallery plus Lightbox <= 2.0 - Unauthenticated Arbitrary Shortcode Execution — Album and Image Gallery Plus LightboxCWE-94 | 6.5 | Medium | 2024-06-06 |
This page lists every published CVE security advisory associated with essentialplugin. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.