Critical Backdoor in WordPress Plugin Affects 20,000 Sites
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A severe supply chain compromise in the Advanced Responsive Video Embedder WordPress plugin has been identified, allowing unauthenticated attackers to gain complete administrator access. The malicious version, 10.8.7, impacts around 20,000 active installations and is tracked as CVE-2026-18072, with a CVSS score of 9.8. The backdoor enables attackers to bypass authentication without any user interaction. This vulnerability was detected by Wordfence's AI threat intelligence system, PRISM. Website owners are urged to take immediate action to secure their sites. The issue was published on 2026-07-29, highlighting the urgency of the situation.
Key Points: • CVE-2026-18072 affects approximately 20,000 WordPress sites. • The vulnerability allows unauthenticated attackers full administrator access. • Website owners should update the Advanced Responsive Video Embedder plugin immediately.