Post #4283906
2026-07-29 13:14 UTC
⚠️ ARVE plugin version 10.8.7 (Advanced Responsive Video Embedder) has a hardcoded backdoor that allows unauthenticated admin access. The plugin repository is currently closed. No patch is available.⚠️
Better uninstall, scan sites and check your registered users.
Details here: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/advanced-responsive-video-embedder/advanced-responsive-video-embedder-for-rumble-odysee-youtube-vimeo-kick-1087-unauthenticated-authentication-bypass-via-hardcoded-backdoor-in-wplogin-parameter
#Wordpress #plugin #security
Replies (0)
No replies.