CVE-2026-66637: WordPress Featured Video Plus plugin <= 2.3.3 - Cross Site Scripting (XSS) vulnerability
Published Aug 18, 2026
·Updated
Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.
Affected Software
1 affected component
WordPress Featured Video Plus plugin<=2.3.3
Event History
Aug 18, 2026
CVE Published
via MITRE·01:59 PM
Data Sourced
via MITRE·01:59 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does an attacker need WordPress access to exploit this issue?
Exploitation requires an authenticated account with low privileges; the vulnerability is specifically associated with Contributor-level access. It is not described as exploitable by an unauthenticated remote attacker.
2
Is user interaction required for exploitation?
Yes. The CVSS vector indicates user interaction is required, so a separate user must interact with the attacker-controlled content for the XSS payload to take effect.