S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Sep 17, 2026

CVE-2026-18072 Scanner

CVE-2026-18072 Scanner - Backdoor vulnerability in Advanced Responsive Video Embedder

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.
Description

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin's source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …by nico23
10.8.7
Updated Sep 17, 2026View on NVD →
Detail

Advanced Responsive Video Embedder is a widely utilized WordPress plugin that caters to web developers and site administrators seeking to incorporate responsive video functionalities in their websites. Employed extensively in the WordPress ecosystem, this plugin enables seamless embedding of videos from platforms like YouTube and Vimeo. It is especially favored by users striving for enhanced media integration. The plugin's user-friendly interface and customizable options make it a valuable resource for enhancing web content. Additionally, site owners and developers utilize it to ensure better user engagement through media content. Its popularity in the WordPress repository underlines its crucial role in digital media management.

The vulnerability detected in Advanced Responsive Video Embedder involves a backdoor authentication bypass. This vulnerability exposes the plugin to unauthorized access, allowing attackers to exploit a hardcoded token. By bypassing authentication measures, attackers can gain administrator-level access to the WordPress site. This vulnerability is particularly concerning due to its potential for complete site takeover. Exploitation of this flaw might lead to unauthorized actions and severe security threats. Immediate attention and rectification of this vulnerability are critical to mitigate potential risks.

The technical details of this vulnerability reveal that it is due to a compromised authentication mechanism in the plugin. Versions 10.8.7 and 10.8.8 accept a hardcoded token through the `_wplogin` parameter. This token triggers a redirect and session-cookie response, setting up an authenticated session for the attacker. The vulnerability resides in the plugin's code, specifically in how it handles authentication requests. The flaw allows a remote attacker to establish an administrator session without proper authentication. This loophole can potentially be used for various malicious activities on the affected WordPress site.

Exploitation of this vulnerability can result in devastating consequences for the affected WordPress sites. Malicious actors can gain full administrator access, leading to complete site control. Possible effects include editing plugins/themes, executing arbitrary PHP code, and data theft. There is a heightened risk of creating rogue administrator accounts and installing web shells. Consequently, the impact of this vulnerability can compromise the integrity and security of the entire website. Immediate remedial actions are imperative to prevent further exploitation.

REFERENCES

Solution Advice
  • Immediately remove versions 10.8.7 and 10.8.8 of the Advanced Responsive Video Embedder plugin from any WordPress installation.
  • Install a clean, non-compromised version of the plugin to replace the backdoored versions.
  • Change all secrets and passwords associated with the WordPress site to ensure they haven't been compromised.
  • Conduct a comprehensive audit of the website to identify and remove any rogue administrator accounts and web shells.
  • Monitor the website closely for any further unauthorized activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2026-18072 Scanner - Backdoor vulnerability in Advanced Responsive Video Embedder | S4E