CVE-2026-66683
Received Received - Intake

Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript

Vulnerability report for CVE-2026-66683, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: Patchstack

Description

Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-06
AI Q&A
2026-08-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
patchstack custom_css_and_javascript to 2.0.16 (inc)
patchstack custom_css_and_javascript_plugin to 2.0.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an unauthenticated sensitive data exposure vulnerability in the Custom CSS and JavaScript WordPress plugin versions 2.0.16 and below. It allows unauthorized users to access sensitive information that should be restricted.

Detection Guidance

Check if the Custom CSS and JavaScript plugin version 2.0.16 or below is installed on your WordPress site. Inspect network traffic for unauthorized access to sensitive data endpoints or exposed files.

Impact Analysis

Attackers could exploit this to gather sensitive data that might help them target other system weaknesses. The impact is considered low severity but still poses a risk to information security.

Mitigation Strategies

Update the plugin to the latest version if available. If no patch exists, consider disabling the plugin temporarily or seek assistance from a hosting provider or web developer to mitigate exposure.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-66683. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart