Description
Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows unauthenticated users to access sensitive data stored by the Custom CSS and JavaScript plugin. This data exposure can lead to the compromise of user credentials, private configuration values, or other personal information, thereby violating confidentiality. The weakness is classified as CWE‑201, indicating improper handling of sensitive information.

Affected Systems

Affected are sites running WP Zone's Custom CSS and JavaScript plugin version 2.0.16 and earlier. No additional product or version details are provided.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. No EPSS score is available, so the exploitation probability is unknown, and the vulnerability is not listed in CISA's KEV catalog. Because the issue is unauthenticated, an attacker only needs to discover a site that has the vulnerable plugin installed and can then retrieve the exposed data by triggering the plugin’s data retrieval endpoint.

Generated by OpenCVE AI on August 6, 2026 at 16:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Custom CSS and JavaScript plugin to version 2.0.17 or later, which addresses the data exposure flaw.
  • Disable or remove the plugin if the added functionality is not required, reducing the attack surface.
  • Conduct a review of all plugin configuration files and delete any residual sensitive data that may still be accessible via exposed endpoints.

Generated by OpenCVE AI on August 6, 2026 at 16:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wp Zone
Wp Zone custom Css And Javascript
Vendors & Products Wordpress
Wordpress wordpress
Wp Zone
Wp Zone custom Css And Javascript

Thu, 06 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.
Title WordPress Custom CSS and JavaScript plugin <= 2.0.16 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress Wordpress
Wp Zone Custom Css And Javascript
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T19:05:30.983Z

Reserved: 2026-07-27T14:01:04.037Z

Link: CVE-2026-66683

cve-icon Vulnrichment

Updated: 2026-08-06T19:05:28.024Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:21.600

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66683

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:59:39Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data