A backdoored ARVE WordPress Plugin release could grant attackers administrator access with one token, but WordPress.org blocked automatic distribution to WordPress sites.

Wordfence has reported the discovery of a critical backdoor within a specific release of the ARVE WordPress Plugin. This vulnerability could have allowed an attacker to gain full administrator access to affected WordPress sites through the use of a single token. However, WordPress.org reportedly took action to prevent the automatic distribution of this compromised plugin version to WordPress installations.
The reported backdoor mechanism involved a specific token that, when exploited, would elevate an attacker's privileges to that of an administrator. This type of access is highly critical as it grants complete control over a WordPress site, including the ability to modify content, install other plugins, themes, or even delete the entire site. The nature of a "backdoor" often implies intentional malicious code inserted into software, designed to bypass normal authentication or authorization mechanisms.
The affected product is the ARVE WordPress Plugin, which is designed to enhance video embedding capabilities on WordPress websites. Plugins are extensions that add new functions to WordPress, and they are widely used across millions of sites. The compromise of a plugin can therefore have a significant impact due to its potential reach.
While the summary indicates that WordPress.org blocked the automatic distribution of the backdoored version, it does not specify if any sites manually installed the compromised release before the block was in place. For users who might have installed the plugin manually from an unofficial source or during a brief window before the block, immediate action would typically involve verifying the integrity of their plugin installations. General mitigation advice for such a scenario includes ensuring all plugins are updated to their latest, trusted versions, removing any suspicious or unknown plugins, and regularly scanning the WordPress installation for malware.
This incident underscores the inherent risks associated with third-party components in web applications. Plugins, themes, and other extensions, while offering immense functionality, also expand the attack surface of a website. The integrity of the supply chain for these components is paramount, as a compromise at any stage can introduce severe vulnerabilities.
The prompt action by WordPress.org to prevent widespread automatic distribution highlights the importance of centralized security monitoring and distribution channels for popular platforms. Such interventions are crucial in mitigating the potential damage from compromised software components before they can be widely exploited.
This event serves as a reminder for website administrators to maintain vigilance over the software they integrate into their platforms, emphasizing the need for regular security audits and adherence to best practices for plugin and theme management.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed