A malicious supply-chain backdoor was discovered in version 10.8.7 of the Advanced Responsive Video Embedder WordPress plugin, tracked as CVE-2026-18072 with a CVSS 9.8 rating. The implanted code introduced an unauthenticated authentication bypass through the _wplogin and _wpm parameters, allowing an attacker to use a hardcoded token from the plugin source to log in as any existing administrator and take full control of a site. The flaw has been classified as CWE-506: Embedded Malicious Code, and reporting indicates the backdoor was likely added after an attacker gained commit access to the developer account.
Wordfence said it detected the malicious release within hours of its introduction and alerted the WordPress.org plugin team, which closed the plugin repository for downloads the same day. Additional reporting said the backdoor also created a persistent admin session, redirected the intruder into the WordPress dashboard, and sent the compromised site URL and impersonated administrator username to attacker-controlled domain fontswp.com. The plugin had roughly 20,000 active installations, although WordPress.org said the malicious version had not been widely distributed through automatic updates; defenders were urged to remove version 10.8.7, install a clean update, and investigate affected sites for signs of compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The WordPress.org plugin repository was closed for downloads on July 28, 2026, in response to the malicious release. WordPress.org also said the compromised version had not yet been broadly distributed through automatic updates.
After detecting the malicious code, Wordfence notified the WordPress.org plugin team on July 28, 2026. This escalated the supply-chain incident to the platform maintainers for response.
Wordfence detected the backdoored plugin release on July 28, 2026, identifying the malicious supply-chain compromise within hours of its introduction. The issue affected the Advanced Responsive Video Embedder plugin, which had about 20,000 active installations.
WordPress.org announced a temporary security measure delaying plugin and theme releases by up to 24 hours before distribution through auto-updates. The change, part of the Protect The Shire initiative, was introduced to improve supply-chain security through additional review, including AI-assisted analysis.
Wordfence said it observed active exploitation of the backdoored ARVE 10.8.7 release and blocked 532 attack attempts in a 24-hour period. The activity showed attackers were already trying to use the hardcoded authentication bypass against vulnerable WordPress sites.
A malicious backdoor was introduced into version 10.8.7 of the Advanced Responsive Video Embedder WordPress plugin, enabling unauthenticated authentication bypass via hardcoded parameters and token checks. The backdoor also sent the compromised site URL and impersonated administrator username to the attacker-controlled domain fontswp.com.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
hackread.com
Open sourcethreataft.com
Open sourcecybersecuritynews.com
Open sourcecvefeed.io
Open sourcewordpress.org
Open sourcewordfence.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.