Imdpen Video Conferencing With Zoom vulnerabilities
3 known vulnerabilities affecting imdpen/video_conferencing_with_zoom.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2024-2031MEDIUMCVSS 5.4fixed in 4.4.52024-03-12
CVE-2024-2031 [MEDIUM] CWE-79 CVE-2024-2031: The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting v
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'zoom_recordings_by_meeting' shortcode in all versions up to, and including, 4.4.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor
nvd
CVE-2023-3947MEDIUMCVSS 5.3≤ 4.2.12023-07-26
CVE-2023-3947 [MEDIUM] CWE-321 CVE-2023-3947: The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposur
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.
nvd
CVE-2022-0384MEDIUMCVSS 4.3fixed in 3.8.172022-03-07
CVE-2022-0384 [MEDIUM] CWE-200 CVE-2022-0384: The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its v
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog
nvd