Weekly Cybersecurity Summary — 24 July to 30 July 2026


CRITICAL WordPress Plugin Supply-Chain Backdoor — Advanced Responsive Video Embedder (CVE-2026-18072)

A malicious version of the WordPress plugin Advanced Responsive Video Embedder, used to embed video from services such as Rumble, Odysee, YouTube, Vimeo and Kick, was published to the WordPress.org plugin repository on 28 July 2026. Version 10.8.7 contained a hidden function, disguised inside an update-check routine, that ran early in WordPress’s request handling and granted full administrator access to anyone who sent a single specially crafted HTTP request, without needing to log in at all. Wordfence’s automated threat intelligence system identified the malicious code within around two hours of it appearing and the WordPress.org team pulled the release the same day, so most sites did not receive it through automatic updates. The plugin has roughly 20,000 active installations.

We will be happy to hear your thoughts

Leave a reply

Som2ny Network
Logo
Register New Account
Compare items
  • Total (0)
Compare
0
Shopping cart