B
今週中
WordPressプラグイン「Advanced Responsive Video Embedder (ARVE)」のバージョン10.8.7にバックドアが仕込まれ…
📌 一言でいうと
WordPressプラグイン「Advanced Responsive Video Embedder (ARVE)」のバージョン10.8.7にバックドアが仕込まれたサプライチェーン攻撃が判明しました。この脆弱性(CVE-2026-18072)はCVSS 9.8と非常に深刻で、攻撃者が単一のHTTPリクエストを送信するだけでサイト管理権限を取得できる可能性があります。WordPress.orgチームは既に当該バージョンのダウンロードを停止していますが、手動インストールしたユーザーは即時の削除が推奨されています。
🔍該当判定
- 自社のWebサイトでWordPressを利用している
- WordPressに「Advanced Responsive Video Embedder (ARVE)」というプラグインをインストールしている
- ARVEのバージョンが「10.8.7」である(手動で更新・導入した場合など)
上記いずれにも該当しない → 静観でOK
✅該当時の対応
ARVEプラグインのバージョンを確認し、10.8.7である場合は直ちに削除または安全なバージョンへの更新を行うこと。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】WordPressプラグイン ARVE (CVE-2026-18072) のバックドア対応について
お疲れさまです。WordPressプラグインのサプライチェーン攻撃に関する情報共有です。
■ 概要
WordPressプラグイン「Advanced Responsive Video Embedder (ARVE)」のバージョン10.8.7にバックドアが植え付けられていることが判明しました。CVSS 9.8の極めて深刻な脆弱性であり、認証をバイパスしてサイト管理権限を奪取される恐れがあります。
■ 影響範囲
- 対象製品: Advanced Responsive Video Embedder (ARVE)
- 対象バージョン: 10.8.7
■ 対応手順
1. 自社管理サイトでARVEプラグインのバージョンを確認してください。
2. バージョン10.8.7がインストールされている場合は、直ちに削除または安全なバージョンへ変更してください。
■ 参考情報
- Wordfence PRISM Threat Intelligence Platform
対応優先度: 高
対応期限: 本日中
お疲れさまです。WordPressプラグインのサプライチェーン攻撃に関する情報共有です。
■ 概要
WordPressプラグイン「Advanced Responsive Video Embedder (ARVE)」のバージョン10.8.7にバックドアが植え付けられていることが判明しました。CVSS 9.8の極めて深刻な脆弱性であり、認証をバイパスしてサイト管理権限を奪取される恐れがあります。
■ 影響範囲
- 対象製品: Advanced Responsive Video Embedder (ARVE)
- 対象バージョン: 10.8.7
■ 対応手順
1. 自社管理サイトでARVEプラグインのバージョンを確認してください。
2. バージョン10.8.7がインストールされている場合は、直ちに削除または安全なバージョンへ変更してください。
■ 参考情報
- Wordfence PRISM Threat Intelligence Platform
対応優先度: 高
対応期限: 本日中
Subject: [Security Alert] Backdoor in WordPress Plugin ARVE (CVE-2026-18072)
Dear IT/Security Team,
We are sharing information regarding a supply chain attack affecting a popular WordPress plugin.
■ Overview
A backdoor has been discovered in version 10.8.7 of the 'Advanced Responsive Video Embedder (ARVE)' plugin. This vulnerability (CVE-2026-18072) has a CVSS score of 9.8, allowing an attacker to bypass authentication and gain full administrative access via a single HTTP request.
■ Scope
- Product: Advanced Responsive Video Embedder (ARVE)
- Affected Version: 10.8.7
■ Action Required
1. Verify the version of the ARVE plugin installed on all managed WordPress sites.
2. If version 10.8.7 is detected, remove the plugin or downgrade/update to a safe version immediately.
■ Reference
- Wordfence PRISM Threat Intelligence Platform
Priority: High
Deadline: Immediate
Dear IT/Security Team,
We are sharing information regarding a supply chain attack affecting a popular WordPress plugin.
■ Overview
A backdoor has been discovered in version 10.8.7 of the 'Advanced Responsive Video Embedder (ARVE)' plugin. This vulnerability (CVE-2026-18072) has a CVSS score of 9.8, allowing an attacker to bypass authentication and gain full administrative access via a single HTTP request.
■ Scope
- Product: Advanced Responsive Video Embedder (ARVE)
- Affected Version: 10.8.7
■ Action Required
1. Verify the version of the ARVE plugin installed on all managed WordPress sites.
2. If version 10.8.7 is detected, remove the plugin or downgrade/update to a safe version immediately.
■ Reference
- Wordfence PRISM Threat Intelligence Platform
Priority: High
Deadline: Immediate