Skip to content

WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2

Cybersecuritynews Abinaya July 29, 2026

A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access. The malicious version, 10.8.7, affects a plugin with roughly 20,000 active installations and is tracked as CVE-2026-18072, with a CVSS score of 9.8. The issue was detected by Wordfence PRISM, the company’s autonomous AI […]

Extracted Entities

Attack Types (1)

Platforms (1)