Skip to content
ThreatCluster

Critical Backdoor in WordPress Plugin Affects 20,000 Sites

First seen 29 Jul 2026, 11:02 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 30, 2026 at 09:22 UTC
  • CVE-2026-18072 affects approximately 20,000 WordPress sites.
  • The vulnerability allows unauthenticated attackers full administrator access.
  • Website owners should update the Advanced Responsive Video Embedder plugin immediately.

A severe supply chain compromise in the Advanced Responsive Video Embedder WordPress plugin has been identified, allowing unauthenticated attackers to gain complete administrator access. The malicious version, 10.8.7, impacts around 20,000 active installations and is tracked as CVE-2026-18072, with a CVSS score of 9.8. The backdoor enables attackers to bypass authentication without any user interaction. This vulnerability was detected by Wordfence's AI threat intelligence system, PRISM. Website owners are urged to take immediate action to secure their sites. The issue was published on 2026-07-29, highlighting the urgency of the situation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 55d ago How this analysis works

Timeline

2026-07-29
CVE-2026-18072 published
A critical vulnerability in the Advanced Responsive Video Embedder plugin was disclosed, affecting 20,000 installations.
Gbhackers
2026-07-29
Backdoor detected by Wordfence
Wordfence's PRISM AI system identified the backdoor authentication bypass in the plugin.
Cybersecuritynews

More articles in this cluster (2)

Following this threat?

Track CVE-2026-18072 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed