WORDPRESS · JULY 2026 · EARLY WARNING

Advanced Responsive Video Embedder WordPress Plugin Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-18072Severity: CRITICAL

The Advanced Responsive Video Embedder plugin for WordPress version 10.8.7 is under investigation for a potential Authentication Bypass vulnerability via a Hardcoded Backdoor, allowing unauthenticated attackers to gain full administrative control.

What happened

The Advanced Responsive Video Embedder plugin for WordPress, used for embedding videos from platforms like Rumble, Odysee, YouTube, Vimeo, and Kick, appears to contain a critical vulnerability in version 10.8.7. This vulnerability, tracked as CVE-2026-18072 with a CVSS score of 9.8, allows unauthenticated attackers to bypass authentication and gain full administrative control over affected WordPress sites. The vulnerability stems from a hardcoded backdoor in the `_arve_uc_init()` function, which compares an attacker-supplied token against a static SHA-256 hash embedded in the plugin source. This hardcoded hash acts as universal credentials, enabling attackers to authenticate as any existing administrator account. WordPress site administrators using version 10.8.7 of this plugin are advised to monitor for updates and consider alternative solutions until a patched version is released. For more details, consult the primary sources linked in the threat data.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If advanced responsive video embedder plugin is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats