logo

Wordfence Finds Critical Backdoor in ARVE WordPress Plugin

ID: 8850fa73-f207-5fba-bff2-3063020d43f4

STIX ID: report--8850fa73-f207-5fba-bff2-3063020d43f4

Feed Name: HackRead

Threat Score
78/100

Date Published: 2026-07-31

Date Updated: 2026-07-31

Author: Waqas

...
...

A malicious backdoor was introduced into the Advanced Responsive Video Embedder (ARVE) WordPress plugin (v10.8.7, CVE-2026-18072). The backdoor registered on init and accepted a fixed SHA256 token via request parameters to log an attacker in as any administrator, create a persistent cookie, and send site and admin username information to an attacker-controlled C2 (fontswp.com). Wordfence detected and verified the injected release within hours and WordPress.org removed the plugin from downloads before automatic updates distributed it, but manually installed or third-party copies of v10.8.7 may still pose a risk; affected sites should remove the version, review admin accounts, invalidate sessions, rotate keys, and inspect for unauthorized changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.