Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … 10.8.7 - 10.8.8 - Unauthenticated Authentication Bypass via Hardcoded Backdoor in '_wplogin' Parameter
criticalThe Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a Hardcoded Backdoor in versions 10.8.7 and 10.8.8. The vulnerability exists because the `_arve_uc_init()` function — registered on WordPress's `init` hook at priority 1 so t...
- CVSS:
- 9.8
- Affected:
- 10.8.7 – 10.8.7, 10.8.8 – 10.8.8
- Fixed in:
- 10.9.0
- Disclosed:
- Jul 28, 2026