Impact
The vulnerability is an unauthenticated sensitive data exposure flaw in the WordPress plugin Featured Video Plus, affecting all versions up to and including 2.3.3. Once triggered, a remote actor can retrieve protected information without needing to authenticate to the WordPress site. The compromised data could include user credentials, email addresses, or other confidential plugin‑related content, thereby violating the confidentiality of the site’s data.
Affected Systems
The affected product is Alex: Featured Video Plus for WordPress. All plugin releases with a version number of 2.3.3 or earlier are vulnerable. The issue is present in the plugin’s code that handles data exposure, impacting any WordPress installation that uses these older plugin versions.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate risk level, and the vulnerability is unauthenticated, meaning attackers can exploit it without authenticating to the WordPress admin interface. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is direct HTTP requests to plugin endpoints that expose sensitive data. The absence of authentication mitigates the necessity for additional attacker privileges, increasing the potential for exploitation.
OpenCVE Enrichment