A critical authentication bypass vulnerability, CVE-2026-18072, affects version 10.8.7 of the Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress, allowing unauthenticated attackers to gain full administrative control by supplying a hardcoded token via the `_wplogin` or `_wpm` URL parameter.
Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin
wordpress
authentication-bypass
web-vulnerability
1r
3t
1c