Authentication Bypass in Advanced Responsive Video Embedder Plugin for WordPress
CVE-2026-18072
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 July 2026
What is CVE-2026-18072?
CVE-2026-18072 is a serious vulnerability that affects the Advanced Responsive Video Embedder Plugin for WordPress, specifically in version 10.8.7. This plugin is widely used to facilitate the embedding of videos from platforms such as YouTube and Vimeo in WordPress sites. The vulnerability arises from an authentication bypass caused by a hardcoded backdoor within the plugin's code. The problematic _arve_uc_init() function is executed during the init hook of WordPress, allowing it to run before any authentication checks. This function compares a supplied token against a hardcoded SHA-256 hash that is embedded in the plugin's source code. Due to the lack of nonce verification, capability checks, and password validation, an unauthenticated attacker can use this known token to gain unauthorized access to the administrative functionalities of the affected WordPress site.
This vulnerability can severely impact organizations, as it enables attackers to potentially take full control of their WordPress installations. By exploiting this flaw, threat actors could change site content, steal sensitive data, and deploy further malicious actions without the need for valid credentials.
Potential Impact of CVE-2026-18072
-
Unauthorized Administrative Access: Attackers can impersonate an existing administrator, gaining unrestricted access to the site's backend and its functionalities, allowing for a range of malicious activities including altering site content and settings.
-
Data Breach Risk: With administrative access at their disposal, attackers can access sensitive user data, potentially leading to data breaches that could harm both the organization and its users. This is particularly concerning for e-commerce sites and those that handle personal information.
-
Malware Deployment: The vulnerability allows attackers to install malicious code or plugins on the compromised WordPress site. This can lead to ransomware attacks, where the site and its data are encrypted, demanding payment for restoration, or it could facilitate further attacks on connected systems.
Affected Version(s)
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7