CVE-2026-18072
nico23 Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick …
The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in version 10.8.7. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so that it runs before any authentication checks on every request — reads an attacker-supplied token from the `_wplogin` (or `_wpm`) parameter and compares it against a hardcoded SHA-256 hash embedded directly in the plugin source, with no nonce verification, no capability check, and no passw...
- CVSS
- 9.8
- EPSS
- 0.59% 44.7% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.29