Earlier this week, WPWithin covered how Wordfence’s AI research tool PRISM had become its top vulnerability finder, logging 202 flaws since May. Today PRISM showed what that speed looks like in a live attack: it caught a backdoor planted inside a plugin used on roughly 20,000 sites, less than two hours after the malicious code appeared.

What happened

On July 28, 2026, Wordfence’s autonomous AI agent PRISM flagged a critical authentication bypass backdoor hidden inside Advanced Responsive Video Embedder, a WordPress plugin with about 20,000 active installations.

This was not a coding mistake. Someone deliberately inserted a hidden function into the plugin’s code. That function let any unauthenticated attacker gain full administrator access to a site by sending a single request containing one hardcoded token. No login, no password, and no user interaction was needed.

Because the code was planted rather than accidentally introduced by the plugin’s developer, Wordfence reported it straight to the WordPress.org plugin team instead of the developer. WordPress.org closed the plugin for downloads immediately.

Who is affected

Any site running the compromised version of Advanced Responsive Video Embedder. Because the backdoor grants full admin access with a single request and no credentials, Wordfence is telling every site owner running that version to treat their site as potentially compromised, not just vulnerable.

Wordfence Premium, Wordfence Care, and Wordfence Response users already have a firewall rule blocking known attacks, deployed the same day the backdoor was found. If you run the free version of Wordfence, that same protection does not arrive until August 27, 2026, a full 30 days later.

What to do

Uninstall Advanced Responsive Video Embedder now if it’s active on your site. Don’t wait for an update, since the plugin has been pulled from WordPress.org and there is no clean version to update to yet.

If your site was running the affected version, assume it may have been accessed by an attacker. Change your WordPress admin passwords, check for unfamiliar admin accounts, and review your site for files or plugins you don’t recognize. If you’re not confident doing that review yourself, bring in a security professional who can check for signs of compromise.

If you use the free version of Wordfence, don’t rely on the 30-day delayed rule alone here. Remove the plugin directly rather than waiting for firewall protection to catch up.


End of article