A vulnerability was found in nico23 Advanced Responsive Video Embedder Plugin 10.8.7 on WordPress and classified as critical. This impacts the function _arve_uc_init. Executing a manipulation of the argument _wplogin/_wpm can lead to backdoor.

This vulnerability is tracked as CVE-2026-18072. The attack can be launched remotely. No exploit exists.