CVE-2026-18072 (matched: wordpress)

  • Wednesday, 29th July, 2026
  • 10:03am

A critical security flaw exists in version 10.8.7 of the Advanced Responsive Video Embedder plugin for WordPress, a tool used to embed videos from platforms including YouTube, Vimeo, Rumble, Odysee, and Kick on your website. The flaw includes a hardcoded hidden backdoor built directly into the plugin’s code. The secret access key required to use this backdoor is publicly visible in the plugin’s source files, meaning any unauthenticated attacker can use it to bypass all standard login protections, log in as any existing administrator on your WordPress site, and take full control of your website. This flaw was likely introduced by an unauthorized party who gained access to the plugin developer’s account to alter the plugin code.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18072

« Back