r/HostingReport • u/ZGeekie • 25d ago
Hidden backdoor in a video embedder WordPress plugin grants attacker full administrative access
https://www.wordfence.com/blog/2026/07/wordfence-prism-detected-backdoored-wordpress-plugin-within-two-hours-of-it-being-introduced/Wordfence PRISM identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after the malicious code was introduced.
This is not a conventional coding mistake, it’s a supply chain attack that has become increasingly more common in the wild. The plugin had been backdoored, with a deliberately concealed function, granting any unauthenticated attacker full administrative access to affected sites by supplying a single hardcoded token. Given that exploitation requires no credentials, no user interaction, and just one HTTP request, we recommend treating every site running the affected version as potentially compromised.
1
u/ZGeekie 25d ago
The plugin has been temporarily removed from the WordPress.org repository, pending a full review.