Exploited in the Wild: CVE-2026-18072 (CVSS 9.8) Grants Full Administrative Control to 20,000 WordPress Sites
ID: da2eee55-abff-5b4a-a0b2-74c9af141c5b
STIX ID: report--da2eee55-abff-5b4a-a0b2-74c9af141c5b
Feed Name: securityonline.info
Threat Score
TL;DR: A malicious backdoor was injected into the Advanced Responsive Video Embedder WordPress plugin (v10.8.7) — CVE-2026-18072 (CVSS 9.8) — allowing attackers to bypass authentication via a 64-character token, force logins as legitimate administrators, and exfiltrate site data to fontswp.com; administrators should remove the plugin, assume compromise, audit accounts, invalidate sessions, rotate keys, and scan for secondary backdoors.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
