CVE-2026-66685 MEDIUM

CVE-2026-66685: WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability

Vendor Alex
Product Featured Video Plus
Weakness CWE-201
Published August 6, 2026
Last update August 6, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.

Explanation of Vulnerability in Simple Terms

02Summary

Featured Video Plus through version 2.3.3 leaks sensitive information in outbound data transmissions. An attacker on the network can intercept unencrypted communications to read exposed details. No authentication or user interaction is required. Site administrators should update to a version newer than 2.3.3.

What an attacker can do

03Attacker Capabilities

Read sensitive information from network traffic sent by the plugin.

Potential impact on your site

04Site Impact

Sensitive data may be exposed to anyone monitoring network traffic between your site and external services.

Conditions required to exploit

05Prerequisites

Network access to intercept unencrypted communications; no authentication required.

Key dates

06Disclosure timeline

August 6, 2026 CVE published
August 6, 2026 Record updated

Related vulnerabilities

08Related CVE