News Security CVE-2026-18072: Backdoored ARVE plugin enables admin logins without credentials July 29, 2026 / July 29, 2026 by Alex Mira | Leave a Comment CVE-2026-18072 affects Advanced Responsive Video Embedder (ARVE) 10.8.7, where a hardcoded backdoor can grant admin access without credentials. Check your version and remove 10.8.7 immediately if present. Read more » ARVE plugin Authentication bypass CVE-2026-18072 incident response plugin supply chain WordPress security