Wordfence Finds Critical Backdoor in ARVE WordPress Plugin
Malicious code added to a WordPress video plugin could have granted full administrator access via a single secret token, but the release was caught before it reached users via WordPress.org automatic updates.
The impacted plugin, called Advanced Responsive Video Embedder (ARVE), helps websites add videos from YouTube, Vimeo, Rumble and other services, and has about 20,000 active installations.
On July 28, Wordfence’s autonomous PRISM system flagged the code less than two hours after its introduction. The company identified the affected release as version 10.8.7, registered as CVE-2026-18072, and rated it critical with a CVSS score of 9.8 out of 10.
Wordfence said the code was likely introduced by an attacker who had gained commit access to the developer’s account. The company’s vulnerability record lists the release as unpatched.
Buried inside a file named php/fn-update-check.php, the backdoor appeared designed to pass as routine plugin update code. Its main...
Copyright of this story solely belongs to hackread.com. To see the full text click HERE