ARVE Plugin Backdoor: Check Your WordPress Site Now
On 28 July 2026, security researchers at Wordfence discovered that version 10.8.7 of the Advanced Responsive Video Embedder (ARVE) WordPress plugin had been deliberately backdoored. Someone had hidden malicious code inside a routine plugin update — code that hands an attacker full administrator access to any WordPress site running it, with no password required.
What is ARVE, and what happened?
ARVE is a popular WordPress plugin that lets website owners embed videos from YouTube, Vimeo, Rumble and other platforms. Around 20,000 websites have the plugin installed. On 28 July, version 10.8.7 was pushed to the plugin repository with malicious code already inside it — a classic supply-chain attack, where an attacker compromises a legitimate software update to distribute malware to trusting users.
The vulnerability is tracked as CVE-2026-18072 and carries a critical severity score of 9.8 out of 10 under the CVSS rating system — the highest category of vulnerability a plugin can receive.
How the backdoor works
The malicious code was added as a function called _arve_uc_init(). This runs in the background on every single page request, before WordPress has checked who the visitor is or whether they are logged in. An attacker simply sends a web request containing a secret token that is hardcoded — baked directly — into the plugin’s source code. WordPress then immediately logs that person in as an existing administrator.
There is no username or password to guess. There is no brute-force attack. Anyone who knows the token can walk straight in.
Wordfence’s automated threat-detection platform spotted the malicious code within two hours of it being introduced on 28 July. WordPress.org has since pulled the plugin from its directory — it is no longer available for download — and the compromised 10.8.7 release did not reach most sites through automatic updates before it was removed.
What could an attacker do with full admin access?
- Install additional malware or redirect your visitors to harmful websites
- Steal customer data, enquiry details, or contact form submissions
- Lock you out of your own website by changing the administrator password
- Deface or take your website down entirely
- Use your website’s reputation and hosting resources to attack others
What SFIT has already done
SFIT manages and hosts WordPress websites for a number of our clients. We audited all managed sites on 29 July and confirmed that none are running the backdoored version 10.8.7. Wordfence Premium firewall protection — which was updated to block exploitation of this backdoor on 28 July — is active across all managed websites we look after.
What you should check if you manage your own WordPress site
If you are responsible for a WordPress website, work through these steps:
- Check your installed plugins. In your WordPress dashboard, go to Plugins and look for “Advanced Responsive Video Embedder” or ARVE. If it shows version 10.8.7, act immediately.
- Remove the plugin entirely. There is no clean, patched replacement currently available — WordPress.org has closed the plugin’s listing. Deactivate and delete it. If you need video embedding, alternatives such as Embed Plus for YouTube are available from the WordPress.org plugin directory.
- Review every administrator account. Go to Users and look at every account with the Administrator role. Remove any you do not recognise and change the passwords on all legitimate accounts.
- Rotate your WordPress security keys. Ask your developer or hosting provider to regenerate your WordPress security keys and salts. This forces all active login sessions to expire, which removes any attacker who may already have gained access.
- Run a security scan. Wordfence Free is available from the WordPress.org plugin directory and will scan your site for known malware, suspicious files, and changes to core files.
If you are running version 10.8.6 or earlier and never updated to 10.8.7, you are not at risk from this specific backdoor. WordPress.org’s response was swift, and the compromised release had limited reach before it was pulled.
A broader lesson: plugin hygiene matters
This incident is a reminder that WordPress security is not just about keeping WordPress core up to date — the plugins you install are equally important. Malicious or compromised plugins are one of the most common ways WordPress sites get hacked. Best practice includes: only installing plugins from trusted, actively maintained sources; removing plugins you no longer use; and monitoring for security disclosures through services such as Wordfence Intelligence or the WordPress Vulnerability Database.
Keeping on top of plugin vulnerabilities is one of the reasons many businesses prefer managed website support rather than doing it themselves. When a critical flaw emerges, the right response needs to happen within hours, not days or weeks.
How SFIT can help
SFIT provides managed IT security services that include WordPress site monitoring, plugin auditing, and rapid incident response when vulnerabilities like this emerge. Our team holds UKAS-accredited ISO/IEC 27001 certification — the international standard for information security management — and we monitor the threat landscape daily so our clients do not have to.
If you are concerned about your website’s security, or would like to talk about what managed IT support looks like for your business, we are happy to help. Our IT support and maintenance service covers ongoing security monitoring and patch management as standard.
Get in touch via our contact form or call us on 01452 701355 for a no-obligation chat.
Stay one step ahead of the threats
Get our free weekly IT and cyber security briefing for UK businesses. The same threat and policy round-up we send our own clients, straight to your inbox. No spam, unsubscribe any time.
Get the free weekly briefing →


