Authentication Bypass in Advanced Responsive Video Embedder Plugin for WordPress
CVE-2026-18072

9.8CRITICAL

What is CVE-2026-18072?

The Advanced Responsive Video Embedder plugin for WordPress suffers from a significant authentication bypass vulnerability due to a hardcoded backdoor. Found in version 10.8.7, this flaw occurs within the _arve_uc_init() function, which is triggered during the init hook of WordPress without proper authentication checks. The function compares a user-supplied token from the _wplogin parameter against a static SHA-256 hash hardcoded into the plugin's source code. As there is no nonce verification, capability validation, or password protection in place, attackers can exploit this vulnerability to authenticate as any existing administrator account by providing the known token. This oversight potentially stems from an attack on the developer's account, allowing unauthorized access and control over the affected WordPress site.

Affected Version(s)

Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wordfence PRISM
.