logo

Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites

ID: da2eee55-abff-5b4a-a0b2-74c9af141c5b

STIX ID: report--da2eee55-abff-5b4a-a0b2-74c9af141c5b

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-07-29

Date Updated: 2026-08-10

Author: Do Son

...
...

TL;DR: A malicious backdoor was injected into the Advanced Responsive Video Embedder WordPress plugin (v10.8.7) — CVE-2026-18072 (CVSS 9.8) — allowing attackers to bypass authentication via a 64-character token, force logins as legitimate administrators, and exfiltrate site data to fontswp.com; administrators should remove the plugin, assume compromise, audit accounts, invalidate sessions, rotate keys, and scan for secondary backdoors.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.