CRITICALAdvisoryAug 02, 2026
Action required
Immediately identify and audit any WordPress installations running ARVE plugin version 10.8.7. Force update to the patched version and review admin logs and user accounts for unauthorized access. Check for C2 communication in network logs to IOCs associated with this campaign.
Affected products
ARVE (Advanced Responsive Video Embedder)WordPress.orgWordfence
CVE IDs
Linked articles