CVE-2026-18072
CVSS 9.8 CRITICAL: the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. EPSS 3% (87th percentile).
Vulnerabilities · 56 days ago
A hidden token in a WordPress plugin can hand over the whole site before normal login checks even run. This is not a broken password flow. It is a built-in trust shortcut that lets an unauthenticated attacker present a known value and be accepted as an existing admin account.
Wordfence PRISM disclosed CVE-2026-18072 in Advanced Responsive Video Embedder v10.8.7. The flaw lets an attacker use the '_wplogin' parameter to authenticate as an arbitrarily chosen administrator, and there is no patch available.
For site operators, the real issue is that the published fix path is removal, not cleanup. Once the plugin is present, it creates a direct path to admin control, so the site stays exposed until the code is gone.
CVSS 9.8 CRITICAL: the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. EPSS 3% (87th percentile).
1 source covering this story
Omisión de autenticación en Advanced Responsive Video Embedder para WordPress
Wordfence PRISM ha informado sobre una vulnerabilidad de severidad crítica que, en caso de ser explota
Part of the PlainSec briefing for 2026-08-03