Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-18072— Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter

Quick assessment

Affected
nico23 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress advanced-responsive-video-embedder是WordPress基金会开源的一款视频嵌入插件。 WordPress advanced-responsive-video-embedder 10.8.7版本存在处理逻辑错误漏洞,该漏洞源于_arve_uc_init函数中存在硬编码后门,未经身份验证的攻击者可通过提供已知token绕过身份认证,获取WordPress站点的完全管理控制权。

CVSS 9.8 · Critical EPSS 2.98% · P87

Public Exploits 1

Affected Version Matrix 1

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-18072

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no password validation anywhere in the flow. Because this static hash constitutes a set of universal credentials that are publicly accessible in the plugin's source code, unauthenticated attackers can supply the known token to be authenticated as an arbitrarily selected existing administrator account, gaining full administrative control over the affected WordPress site. This was likely introduced by an attacker who gained commit access to the developers account.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
内嵌的恶意代码
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress advanced-responsive-video-embedder 处理逻辑错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress advanced-responsive-video-embedder是WordPress基金会开源的一款视频嵌入插件。 WordPress advanced-responsive-video-embedder 10.8.7版本存在处理逻辑错误漏洞,该漏洞源于_arve_uc_init函数中存在硬编码后门,未经身份验证的攻击者可通过提供已知token绕过身份认证,获取WordPress站点的完全管理控制权。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
nico23 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 -

II. Public POCs for CVE-2026-18072

# POC Description Source Link Shenlong Link
1 The compromised Advanced Responsive Video Embedder WordPress plugin releases 10.8.7 and 10.8.8 accept a hardcoded token through the `_wplogin` parameter and establish an authenticated administrator session before normal authentication. A single unauthenticated GET request triggers the backdoor. This template only inspects the redirect and session-cookie response and does not perform any administrative action. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-18072.yaml POC Details
AI-Generated POC Premium
default-local-qwen3.6 · 11181 chars
Pro+ exclusive includes:
Vulnerability reproduction recording (real sandbox build + trigger, exclusive)
In-depth vulnerability mechanism
Trigger conditions & impact
Full executable POC code
Exploit chain & mitigation
POC zip download
100+ AI POC generations per month

III. Intelligence Information for CVE-2026-18072

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-18072 (3)

News Coverage for CVE-2026-18072 (1)

Other References for CVE-2026-18072 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-18072

No comments yet


Leave a comment