THREAT OPS › Threat News › Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
Wordfence PRISM Detected Backdoored WordPress Plugin within Two Hours of it Being Introduced
<p>On July 28th, 2026, our autonomous AI vulnerability intelligence agent, <a href="https://www.wordfence.com/threat-intel/vulnerabilities/researchers/id/6344">Wordfence PRISM</a>, identified a critical Authentication Bypass backdoor in Advanced Responsive Video Embedder, a WordPress plugin with approximately 20,000 active installations, less than two hours after the malicious code was introduced.
MITRE ATT&CK techniques
Indicators of compromise
- 35fe7057ffed92ff7bc5a0b90f302a77fb5843ad6c972294d68da0b0553b3900sha256
- b0bd54077fbac807142b902c61d6430cmd5
- CVE-2026-18072cve
- https://www.cve.org/CVERecord?id=CVE-2026-18072url
- https://fontswp.com/arve/cb.php?s=".urlencode($s)."&u=".urlencode($u)."&v=".urlencode($vurl
- wordpress.orgdomain
- www.gravatar.comdomain