Authentication Bypass in Advanced Responsive Video Embedder Plugin for WordPress
CVE-2026-18072
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-18072?
The Advanced Responsive Video Embedder plugin for WordPress suffers from a significant authentication bypass vulnerability due to a hardcoded backdoor. Found in version 10.8.7, this flaw occurs within the _arve_uc_init() function, which is triggered during the init hook of WordPress without proper authentication checks. The function compares a user-supplied token from the _wplogin parameter against a static SHA-256 hash hardcoded into the plugin's source code. As there is no nonce verification, capability validation, or password protection in place, attackers can exploit this vulnerability to authenticate as any existing administrator account by providing the known token. This oversight potentially stems from an attack on the developer's account, allowing unauthorized access and control over the affected WordPress site.
Affected Version(s)
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7