Junglewise Threat Intelligence

CVE-2026-66685: Featured Video Plus sensitive data exposure

CVE-2026-66685 · Severity: medium · CVSS 5.3 · Published 2026-08-06

Vendors: Wordpress.

Executive brief

Featured Video Plus is a popular WordPress plugin used to embed and display video content on websites. Versions up to 2.3.3 suffer from an unauthenticated information disclosure flaw that allows attackers to access sensitive data without requiring a login or special permissions. Exploiting this vulnerability could expose private information such as email addresses, payment details, or other confidential data stored on affected websites.

Technical details

The vulnerability is classified as sensitive data exposure affecting Featured Video Plus plugin versions 2.3.3 and earlier. It requires no authentication to exploit and can be triggered over the network, meaning any attacker with access to the affected WordPress installation can retrieve private information. The exact mechanism of exposure is not detailed in the advisory, but the unauthenticated attack vector and ability to access sensitive data suggests inadequate access controls or improper data filtering on an exposed endpoint or REST API. No official patch has been released at the time of publication; users should update to a patched version when available or implement access controls at the server level.

Affected products

  • WordPress Featured Video Plus ≤ 2.3.3

Timeline

  • 2026-07-08: disclosed: Vulnerability reported to Patchstack
  • 2026-08-06: advisory: Published by Patchstack and NVD

References