Video Conferencing with Zoom <= 3.8.16 - E-mail Address Disclosure
2022-02-14 00:00
Krzysztof ZającStrategic Overview
StatusPatched in 3.8.17
Affected PluginVideo Conferencing with Zoom
Affected Version
< 3.8.17CVSS4.3Medium
CVE
CVE-2022-0384Vulnerability Overview
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog
Technical Analysis
REMEDIATION: Update to version 3.8.17, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C