top of page
perceptive_background_267k.jpg

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Ba…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 06:00:56

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Supply Chain & Dependencies, Identity & Access, Zero-Day Vulnerabilities

CVE-2026-18072 affects the Advanced Responsive Video Embedder WordPress plugin version 10.8.7, which contains a hardcoded backdoor enabling full authentication bypass. The vulnerability resides in the `_arve_uc_init()` function, registered at WordPress `init` hook priority 1, which runs before any authentication checks. An attacker-supplied token via `_wplogin` or `_wpm` parameters is compared against a hardcoded SHA-256 hash embedded in the plugin source code. This allows unauthenticated attackers to authenticate as any existing administrator account without any nonce, capability, or password validation. The backdoor was likely introduced through a supply chain attack where a threat actor gained commit access to the developer's account. The vulnerability grants full administrative control over affected WordPress sites. Given the publicly accessible nature of the hardcoded hash in the plugin source, exploitation is trivial and highly likely.

Technical details

Mitigation steps:

Affected products:

Advanced Responsive Video Embedder WordPress Plugin 10.8.7

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page