Unauthenticated Sensitive Data Exposure in Featured Video Plus Plugin by WordPress
CVE-2026-66685
5.3MEDIUM
What is CVE-2026-66685?
The Featured Video Plus plugin for WordPress, up to version 2.3.3, contains a vulnerability that allows unauthorized access to sensitive data. This exposure can potentially lead to the leakage of private information, making it imperative for website administrators to take action. Users of the plugin should promptly update to the latest version to mitigate the risks associated with this security issue and reinforce their site's safety.
Affected Version(s)
Featured Video Plus <= 2.3.3
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program