A vulnerability was found in nico23 Advanced Responsive Video Embedder Plugin 10.8.7 on WordPress and classified as critical. This impacts the function
_arve_uc_init. Executing a manipulation of the argument _wplogin/_wpm can lead to backdoor.
This vulnerability is tracked as CVE-2026-18072. The attack can be launched remotely. No exploit exists.