


Perceptive Security
SOC/SIEM Consultancy

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Ba…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 06:00:56
Source:
nvd.nist.gov
Web Technologies, Supply Chain & Dependencies, Identity & Access, Zero-Day Vulnerabilities
CVE-2026-18072 affects the Advanced Responsive Video Embedder WordPress plugin version 10.8.7, which contains a hardcoded backdoor enabling full authentication bypass. The vulnerability resides in the `_arve_uc_init()` function, registered at WordPress `init` hook priority 1, which runs before any authentication checks. An attacker-supplied token via `_wplogin` or `_wpm` parameters is compared against a hardcoded SHA-256 hash embedded in the plugin source code. This allows unauthenticated attackers to authenticate as any existing administrator account without any nonce, capability, or password validation. The backdoor was likely introduced through a supply chain attack where a threat actor gained commit access to the developer's account. The vulnerability grants full administrative control over affected WordPress sites. Given the publicly accessible nature of the hardcoded hash in the plugin source, exploitation is trivial and highly likely.
Technical details
Mitigation steps:
Affected products:
Advanced Responsive Video Embedder WordPress Plugin 10.8.7
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-18072
https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/advanced-responsive-video-embedder.php#L76
https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/php/fn-update-check.php#L24
https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/php/fn-update-check.php#L33
https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/php/fn-update-check.php#L52
https://www.wordfence.com/threat-intel/vulnerabilities/id/70f64ea0-5375-479f-90ac-29bcdf817cef?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
