CVE-2026-18072 is an intentional embedded backdoor in version 10.8.7 of the Advanced Responsive Video Embedder for WordPress plugin. A routine registered at very early WordPress initialization processes an attacker-controlled login token before normal authentication, then compares it with a static SHA-256-derived value embedded in the plugin source. The flow performs no password validation, nonce validation, or authorization check. Possession of the publicly recoverable token permits unauthenticated authentication as an existing administrator account.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
15 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Unknown; the content only references the CVE identifier and provides no vulnerability, affected-product, impact, or exploitation details.
A specific vulnerability tied to the Advanced Responsive Video Embedder WordPress plugin, mentioned as part of related software supply chain attacks linked by shared C2 infrastructure.
A critical backdoor in the Advanced Responsive Video Embedder (ARVE) WordPress plugin version 10.8.7 that could allow an attacker to gain administrator access using a hardcoded token and create a persistent authenticated session.
A critical authentication bypass vulnerability caused by an intentional hardcoded backdoor in ARVE WordPress plugin version 10.8.7, enabling unauthenticated full administrative takeover of affected WordPress sites.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.