PT-2026-65688 · WordPress · Advanced Responsive Video Embedder

·

CVE-2026-18072

·

Published

2026-07-29

·

Updated

2026-07-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … version 10.8.7
Description An authentication bypass exists due to a hardcoded backdoor. The arve uc init() function, which executes before authentication checks on every request, processes a token provided via the wplogin or wpm parameters. This token is compared against a static SHA-256 hash embedded in the plugin source code without nonce verification, capability checks, or password validation. Since this hash is publicly accessible, unauthenticated attackers can use the token to authenticate as any existing administrator account and gain full control of the WordPress site.
Recommendations For version 10.8.7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-18072

Affected Products

Advanced Responsive Video Embedder