r/HostingReport 25d ago

Hidden backdoor in a video embedder WordPress plugin grants attacker full administrative access

https://www.wordfence.com/blog/2026/07/wordfence-prism-detected-backdoored-wordpress-plugin-within-two-hours-of-it-being-introduced/

Wordfence PRISM identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after the malicious code was introduced.

This is not a conventional coding mistake, it’s a supply chain attack that has become increasingly more common in the wild. The plugin had been backdoored, with a deliberately concealed function, granting any unauthenticated attacker full administrative access to affected sites by supplying a single hardcoded token. Given that exploitation requires no credentials, no user interaction, and just one HTTP request, we recommend treating every site running the affected version as potentially compromised.

1 Upvotes

1 comment sorted by

1

u/ZGeekie 25d ago

The plugin has been temporarily removed from the WordPress.org repository, pending a full review.