PT-2026-65688 · WordPress · Advanced Responsive Video Embedder
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … version 10.8.7
Description
An authentication bypass exists due to a hardcoded backdoor. The
arve uc init() function, which executes before authentication checks on every request, processes a token provided via the wplogin or wpm parameters. This token is compared against a static SHA-256 hash embedded in the plugin source code without nonce verification, capability checks, or password validation. Since this hash is publicly accessible, unauthenticated attackers can use the token to authenticate as any existing administrator account and gain full control of the WordPress site.Recommendations
For version 10.8.7, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Advanced Responsive Video Embedder