Description
Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Published: 2026-08-06
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated sensitive data exposure flaw in the WordPress plugin Featured Video Plus, affecting all versions up to and including 2.3.3. Once triggered, a remote actor can retrieve protected information without needing to authenticate to the WordPress site. The compromised data could include user credentials, email addresses, or other confidential plugin‑related content, thereby violating the confidentiality of the site’s data.

Affected Systems

The affected product is Alex: Featured Video Plus for WordPress. All plugin releases with a version number of 2.3.3 or earlier are vulnerable. The issue is present in the plugin’s code that handles data exposure, impacting any WordPress installation that uses these older plugin versions.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate risk level, and the vulnerability is unauthenticated, meaning attackers can exploit it without authenticating to the WordPress admin interface. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is direct HTTP requests to plugin endpoints that expose sensitive data. The absence of authentication mitigates the necessity for additional attacker privileges, increasing the potential for exploitation.

Generated by OpenCVE AI on August 6, 2026 at 16:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Featured Video Plus to version 2.3.4 or newer to eliminate the vulnerable code.
  • Verify that the WordPress installation is running the patched plugin version and that any old plugin files have been removed from the server.
  • If an immediate upgrade is not possible, temporarily disable the plugin or restrict access to its endpoints using a web‑application firewall or .htaccess rules to prevent unauthenticated data access.

Generated by OpenCVE AI on August 6, 2026 at 16:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Alex
Alex featured Video Plus
Wordpress
Wordpress wordpress
Vendors & Products Alex
Alex featured Video Plus
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.
Title WordPress Featured Video Plus plugin <= 2.3.3 - Sensitive Data Exposure vulnerability
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Alex Featured Video Plus
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T16:43:23.120Z

Reserved: 2026-07-27T14:01:04.038Z

Link: CVE-2026-66685

cve-icon Vulnrichment

Updated: 2026-08-06T16:43:14.544Z

cve-icon NVD

Status : Deferred

Published: 2026-08-06T15:17:21.853

Modified: 2026-08-12T20:58:37.847

Link: CVE-2026-66685

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T09:59:38Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data