Unknown Video Conferencing With Zoom vulnerabilities
3 known vulnerabilities affecting unknown/video_conferencing_with_zoom.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-1368HIGHCVSS 7.5fixed in 4.6.62026-02-18
CVE-2026-1368 [HIGH] CWE-287 CVE-2026-1368: The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its
The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
cvelistv5nvd
CVE-2022-4578MEDIUMCVSS 5.4fixed in 4.0.102023-01-16
CVE-2022-4578 [MEDIUM] CWE-79 CVE-2022-4578: The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of
The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
cvelistv5nvd
CVE-2022-0384MEDIUMCVSS 4.3≥ 3.8.17, < 3.8.172022-03-07
CVE-2022-0384 [MEDIUM] CWE-200 CVE-2022-0384: The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its v
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog
cvelistv5nvd