Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Backdoor in WordPress Plugin Exposes Admin Access

Critical Backdoor in WordPress Plugin Exposes Admin Access

Posted on July 29, 2026 By CWS

A severe security issue has been uncovered in the Advanced Responsive Video Embedder plugin for WordPress, endangering approximately 20,000 active installations. This vulnerability, identified as CVE-2026-18072, could grant unauthenticated users complete administrative access, with a CVSS score of 9.8, highlighting its critical nature.

Discovery and Technical Details

The vulnerability was first identified by Wordfence PRISM, an advanced AI-driven vulnerability detection system, on July 28, 2026. It was detected merely hours after the introduction of the malicious code, marking a significant breach in the plugin’s distribution chain.

This backdoor is hidden within a file named php/fn-update-check.php, which the plugin loads automatically. The function _arve_uc_init() executes early during WordPress’s request process, bypassing typical authentication checks. Attackers can exploit this by using specific request parameters to gain access.

Mechanism of the Attack

The attack is facilitated through attacker-supplied parameters that are verified against a visible SHA-256 token in the plugin’s code. This token acts as a universal credential, enabling attackers to bypass the usual security measures without needing any valid WordPress credentials.

Once the token is validated, the backdoor identifies an administrator account to impersonate, deliberately avoiding usernames that could be controlled by the attackers themselves. This leads to the creation of a persistent admin session, granting the attacker access to the WordPress admin dashboard.

The backdoor also communicates with a command-and-control server, fontswp.com, sending details of compromised sites and admin usernames, which helps attackers track and prioritize their targets.

Response and Mitigation Measures

Wordfence promptly informed the WordPress.org plugin team, resulting in the closure of the plugin’s download repository on the same day. Although the malicious version had not been widely distributed via automatic updates, site administrators are urged to verify plugin versions and check for any signs of compromise.

Recommended actions include auditing admin accounts, revoking active sessions, rotating WordPress secret keys, resetting privileged credentials, and examining files and databases for any unauthorized changes. Additionally, blocking outgoing connections to fontswp.com is advised to prevent further unauthorized data transmission.

In light of this incident, it is essential for organizations to strengthen their security operations centers (SOC) by adopting tools like ANY.RUN to accelerate threat detection and response times.

Cyber Security News Tags:administrator access, Backdoor, CVE-2026-18072, Cybersecurity, Malware, PHP, Plugin, Security, supply chain attack, Vulnerability, website security, Wordfence, WordPress

Post navigation

Previous Post: Spur Secures $200M to Enhance IP Intelligence Services
Next Post: Gitea Patches Critical RCE Vulnerability in Git Hooks

Related Posts

Microsoft Enhances Teams with AI-Powered Workflows Microsoft Enhances Teams with AI-Powered Workflows Cyber Security News
L7 DDoS Botnet Hijacked 5.76M Devices to Launch Massive Attacks L7 DDoS Botnet Hijacked 5.76M Devices to Launch Massive Attacks Cyber Security News
PoC Exploit Released for ImageMagick RCE Vulnerability PoC Exploit Released for ImageMagick RCE Vulnerability Cyber Security News
New Banking Malware DoubleTrouble Attacking Users Via Phishing Sites To Steal Banking Credentials New Banking Malware DoubleTrouble Attacking Users Via Phishing Sites To Steal Banking Credentials Cyber Security News
Rockstar Data Breach: 78.6 Million Records Exposed Rockstar Data Breach: 78.6 Million Records Exposed Cyber Security News
RedNovember Hackers Attacking Government and Technology Organizations to Deploy Backdoor RedNovember Hackers Attacking Government and Technology Organizations to Deploy Backdoor Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Gitea Security Flaw Permits Remote Code Execution
  • OpenAI’s AI Models Breach Hugging Face Systems
  • Gitea Patches Critical RCE Vulnerability in Git Hooks
  • Critical Backdoor in WordPress Plugin Exposes Admin Access
  • Spur Secures $200M to Enhance IP Intelligence Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Gitea Security Flaw Permits Remote Code Execution
  • OpenAI’s AI Models Breach Hugging Face Systems
  • Gitea Patches Critical RCE Vulnerability in Git Hooks
  • Critical Backdoor in WordPress Plugin Exposes Admin Access
  • Spur Secures $200M to Enhance IP Intelligence Services

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark