WordPress – Backdoor Plugin

Overview

A critical supply chain backdoor has been discovered in the Advanced Responsive Video Embedder (ARVE) WordPress plugin, affecting roughly 20,000 active installations. Tracked as CVE‑2026‑18072 with a CVSS score of 9.8, the malicious version (10.8.7) allows unauthenticated attackers to gain full administrator access and exfiltrate site details to an attacker‑controlled command‑and‑control (C2) server.

How the Backdoor Works

  • Malicious file: Hidden in php/fn-update-check.php.
  • Execution: Runs early in WordPress’s lifecycle via _arve_uc_init(), before authentication checks.
  • Trigger: Accepts attacker‑controlled values through _wplogin or _wpm parameters (URL, form, or cookie).
  • Token validation: Uses a hardcoded SHA‑256 token embedded in source code, visible to anyone.
  • Admin impersonation: Selects an administrator account (excluding usernames like wpsvc_, developer_, dev_, wp_update_).
  • Persistent session: Creates a lasting WordPress login session and redirects attacker to the admin dashboard.
  • Data exfiltration: Sends site URL and impersonated admin username to fontswp.com.

Why It’s Dangerous

  • Exploitation requires only one crafted HTTP request.
  • No brute‑forcing, phishing, or prior access is needed.
  • A vulnerable site can be fully compromised in seconds.

Discovery and Response

  • Detected by Wordfence PRISM, an autonomous AI vulnerability intelligence agent, on July 28, 2026, less than two hours after malicious code was introduced.
  • WordPress.org plugin team was notified immediately; the repository was closed for downloads the same day.
  • The malicious release had not yet been broadly distributed via automatic updates, but organizations must still verify installed versions.

Defensive Guidance

Administrators should:

  • Check installed plugin versions and remove version 10.8.7.
  • Audit administrator accounts for unauthorized impersonation.
  • Invalidate active sessions and rotate WordPress secret keys.
  • Reset privileged credentials immediately.
  • Inspect files and databases for hidden malware or unauthorized changes.
  • Block outbound connections to fontswp.com.

Expert in the Cloud Insight

This incident highlights the growing risk of supply chain compromises in WordPress plugins. Unlike traditional vulnerabilities, this was a deliberate backdoor insertion, meaning attackers directly targeted the plugin’s distribution channel. For enterprises, the lesson is clear: plugin trust must be continuously verified. Automated monitoring, rapid patching, and strict outbound traffic controls are essential to defend against supply chain threats that bypass traditional vulnerability models.

Be the first to comment

Leave a Reply

Your email address will not be published.


*


This site uses Akismet to reduce spam. Learn how your comment data is processed.