A critical vulnerability has been assigned to Advanced Responsive Video Embedder (ARVE) for WordPress under CVE-2026-18072. According to Wordfence, version 10.8.7 of the plugin contained a deliberately added backdoor that can grant full administrator access to a site without any valid credentials. The WordPress.org plugin team has closed the plugin for downloads. Wordfence also reports that the compromised release had not yet been automatically distributed at the time of their disclosure, but site owners should still verify their installed version.
What the vulnerability does
Wordfence’s technical analysis describes a function introduced in ARVE 10.8.7 that runs very early in WordPress’s bootstrap sequence. It inspects an incoming request parameter and compares its value to a hardcoded hash present in the plugin code. When the value matches, the logic selects an existing administrator account on the site and establishes a logged-in session for that user, effectively bypassing normal authentication. Wordfence further notes that the code sends basic site and user information to an external domain and then redirects the requester into the WordPress dashboard.
This behavior requires no prior authentication, no user interaction, and can be triggered in a single request. Wordfence characterizes the change as a supply chain backdoor rather than an accidental coding error. Their write-up lists the issue as affecting ARVE 10.8.7 with a CVSS score of 9.8 (Critical) and reports the status as unpatched.
Relevant references:
- Wordfence disclosure: https://www.wordfence.com/blog/2026/07/wordfence-prism-detected-backdoored-wordpress-plugin-within-two-hours-of-it-being-introduced/
- WordPress.org repository tag for 10.8.7 (source browser): https://plugins.trac.wordpress.org/browser/advanced-responsive-video-embedder/tags/10.8.7/advanced-responsive-video-embedder.php
Why it matters
A one-request admin login bypass is about as high-impact as it gets for WordPress sites. If present, an attacker could change content, install additional plugins, add users, or exfiltrate data under the guise of a legitimate administrator account. Wordfence notes ARVE had a sizable install base, making rapid awareness and version checks important even if the malicious release was not broadly auto-distributed.
What site owners should do now
Based on Wordfence’s advisory and the plugin repository status, a practical response is to:
- Identify whether ARVE is installed and confirm the version. If version 10.8.7 is present, remove the plugin immediately.
- If 10.8.7 was ever active on a site, treat the site as potentially compromised and conduct a thorough review for unauthorized administrator activity.
- Note that Wordfence reports the plugin has been closed for downloads on WordPress.org and that its users on paid tiers received a firewall rule on July 28, 2026, with free-tier protection scheduled 30 days later.
If ARVE is not installed, or if your site never received version 10.8.7, no immediate action is indicated beyond routine vigilance.
What’s confirmed vs. unclear
Confirmed by Wordfence’s report:
- The backdoor is present in ARVE 10.8.7 and enables unauthenticated admin logins via a hardcoded token check.
- WordPress.org closed the plugin for downloads; Wordfence states the compromised release was not yet automatically distributed.
- Affected version: 10.8.7. CVE: CVE-2026-18072. Severity noted as Critical (CVSS 9.8). Patch status listed as unpatched at the time of publication.
Unclear at this time:
- The origin of the injected code and the complete distribution scope.
- Whether any sites were actually compromised in the wild. Wordfence recommends treating sites on 10.8.7 as potentially affected but does not provide incident counts.
Bottom line
CVE-2026-18072 describes a high-severity backdoor in ARVE 10.8.7 that can hand over administrator access without a password. If you run ARVE, verify your installed version and remove 10.8.7 immediately if present. Continue watching the plugin’s repository and trusted security advisories for remediation updates.
—
Author: Alex Mira, AI Research Writer at Toolslib
Disclosure: Alex Mira is a fictitious AI-assisted author created for the Toolslib blog. Content under this profile follows Toolslib’s editorial standards.
Alex Mira is a fictitious AI-assisted author created for the Toolslib blog. Designed to support cybersecurity education, Alex writes about malware trends, software utilities, privacy practices, Windows internals, and practical defensive workflows. Articles published under Alex’s name are generated or assisted by AI and reviewed according to Toolslib’s editorial standards before publication.
Stay Updated with ToolsLib! 🚀
Join our community to receive the latest cybersecurity tips, software updates, and exclusive insights straight to your inbox!