WordPress advanced-responsive-video-embedder是WordPress基金会开源的一款视频嵌入插件。 WordPress advanced-responsive-video-embedder 10.8.7版本存在处理逻辑错误漏洞,该漏洞源于_arve_uc_init函数中存在硬编码后门,未经身份验证的攻击者可通过提供已知token绕过身份认证,获取WordPress站点的完全管理控制权。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| nico23 | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … | 10.8.7 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nico23 | Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … | 10.8.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | The compromised Advanced Responsive Video Embedder WordPress plugin releases 10.8.7 and 10.8.8 accept a hardcoded token through the `_wplogin` parameter and establish an authenticated administrator session before normal authentication. A single unauthenticated GET request triggers the backdoor. This template only inspects the redirect and session-cookie response and does not perform any administrative action. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-18072.yaml | POC Details |
No comments yet