Sceawere

Vulnerability Detail

CVE-2026-66685UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Sensitive Data Exposure in Featured Video Plus

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
1d ago
Vendor
Alex
Product
Featured Video Plus
Attack Type
CWE-201 Insertion of Sensitive Information Into Sent Data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-08-06T15:17:21.853Z",
  "pubdate": "2026-08-06T15:17:21.853Z",
  "executiveSummary": "An unauthenticated sensitive data exposure vulnerability has been identified in the Featured Video Plus plugin affecting versions 2.3.3 and below. This security flaw allows unauthenticated remote actors to access sensitive information without requiring prior authorization or interaction with high-privileged accounts. The vulnerability exposes critical internal data, significantly increasing the attack surface of the hosting web application. Risk implications include unauthorized intelligence gathering, potential exposure of personally identifiable information or system credentials, and facilitation of subsequent multi-stage cyber attacks. The lack of proper access controls and session validation mechanisms on vulnerable endpoints enables threat actors to query and retrieve restricted payloads directly over the network. Exploitation requirements are minimal, as the flaw resides in unauthenticated routines, allowing automated scripts or remote adversaries to harvest sensitive application state data effortlessly. Immediate remediation is required to restrict unauthorized access and protect underlying system confidentiality.",
  "technicalDetails": "The vulnerability manifests as an unauthenticated sensitive data exposure within the Featured Video Plus plugin for versions 2.3.3 and below. The root cause of the flaw stems from improper access control enforcement and missing authorization checks within specific plugin components or endpoints responsible for handling data retrieval and rendering operations. Specifically, the affected component fails to validate whether incoming HTTP requests originate from authenticated users possessing administrative or authorized operational privileges.\nNetwork exposure is external, meaning any remote attacker with network connectivity to the vulnerable WordPress installation can interact with the exposed endpoint via standard HTTP/HTTPS protocols. No prior authentication, session cookies, or special privilege levels are required to initiate and complete the attack sequence, classifying the vulnerability as an unauthenticated vector.\nThe attack flow proceeds as follows: First, the remote adversary identifies the presence of the vulnerable Featured Video Plus plugin version 2.3.3 or lower through fingerprinting or version enumeration techniques. Second, the attacker crafts a targeted HTTP request directed toward the unprotected functional component or endpoint responsible for processing video metadata or internal configurations. Third, because the underlying code lacks requisite capability checks and session validations, the application processes the request and returns the requested payload containing sensitive data directly in the HTTP response body.\nThe post-exploitation impact primarily centers on confidentiality breaches. By harvesting sensitive information exposed through this endpoint, attackers can acquire internal path structures, configuration parameters, or supplementary application data. This extracted intelligence can subsequently be leveraged to mount advanced pivot attacks, orchestrate targeted exploitation of other discovered plugins, or compromise the broader content management system environment. Remediation requires updating the plugin to a patched version where robust access control lists and proper authentication checks are enforced on all sensitive data handling routines."
}
CVE-2026-66685: Unauthenticated Sensitive Data Exposure in Featured Video Plus (MEDIUM Severity, CVSS: 5.3) - Sceawere