securityonline.info 7/29/2026, 8:13:49 AM · external

CVE-2026-18072 backdoor in WordPress video plugin exploited

CVE-2026-18072 backdoor in WordPress video plugin exploited
CyberSIXT Evidence Panel
Primary Source wordfence.com
CVE Intel
CISA KEV Not in KEV
Patch Patch Available

THE content discusses a critical cybersecurity vulnerability identified as CVE-2026-18072, affecting the Advanced Responsive Video Embedder plugin for WordPress. This backdoor allows attackers to bypass authentication entirely, granting them full administrative control to affected websites. Approximately 20,000 installations are at risk, especially since hackers are actively exploiting this flaw.

The backdoor operates by injecting a malicious function that validates a specific token, allowing attackers to log in as legitimate administrators. Users are advised to immediately remove the plugin, audit accounts, invalidate sessions, and scan their sites for any secondary threats.

View Primary Source Via securityonline.info

Article by CyberSIXT