What is CVE-2026-18072?
The Advanced Responsive Video Embedder plugin for WordPress, version 10.8.7, contains a hardcoded backdoor via the `_arve_uc_init()` function, allowing authentication bypass. Users must update to the latest patched version immediately.
Azərbaycanca: WordPress üçün Advanced Responsive Video Embedder plaginin 10.8.7 versiyasında `_arve_uc_init()` funksiyası vasitəsilə sabit kodlanmış arxa qapı (hardcoded backdoor) aşkarlanıb. Bu boşluq autentifikasiyadan yan keçməyə imkan verir. Plaginin istifadəçiləri dərhal ən son təhlükəsiz versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-798
FAQ1
What vulnerability was discovered in version 10.8.7 of the WordPress Advanced Responsive Video Embedder plugin?
A hardcoded backdoor was discovered in the plugin's `_arve_uc_init()` function, allowing authentication bypass.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.