WordPress Plugin Backdoor Sends Site and Administrator Details to Attacker C2

A critical supply chain backdoor in the Advanced Responsive Video Embedder WordPress plugin, which can give unauthenticated attackers complete administrator access. The malicious version, 10.8.7, affects a plugin with roughly 20,000 active installations and is tracked as CVE-2026-18072, with a CVSS score of 9.8. The issue was detected by Wordfence PRISM, the company’s autonomous AI […]

This article has been indexed from Cyber Security News

Read the original article: