[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:wordfence-finds-critical-backdoor-in-arve-wordpress-plugin-msbmx8gr":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":13,"action_required":17,"article_ids":18,"ioc_summary":20,"source_urls":21,"status":23,"expires_at":24,"created_at":25,"updated_at":26,"articles":27},"27a2b234-fda2-4e44-982b-96a362eb305c","Wordfence Finds Critical Backdoor in ARVE WordPress Plugin","wordfence-finds-critical-backdoor-in-arve-wordpress-plugin-msbmx8gr","A backdoored version 10.8.7 of the ARVE WordPress plugin was released with malicious code granting full admin access via secret token. ~20,000 active installations were at risk before WordPress.org blocked distribution. The attacker likely compromised the developer's account to inject the backdoor and exfiltrate credentials to a C2 server.","critical","advisory",[12],"CVE-2026-18072",[14,15,16],"ARVE (Advanced Responsive Video Embedder)","WordPress.org","Wordfence","Immediately identify and audit any WordPress installations running ARVE plugin version 10.8.7. Force update to the patched version and review admin logs and user accounts for unauthorized access. Check for C2 communication in network logs to IOCs associated with this campaign.",[19],"d1accfd8-0af9-46c8-9c12-5336f42d3b4a",null,[22],"https:\u002F\u002Fhackread.com\u002Fwordfence-critical-backdoor-arve-wordpress-plugin\u002F","active","2026-08-04T10:05:42.663+00:00","2026-08-02T10:05:45.761184+00:00","2026-08-02T10:06:34.06699+00:00",[28],{"id":19,"title":6,"url":22}]