PT-2022-13143 · Zoom · Video Conferencing With Zoom Wordpress Plugin

Krzysztof Zając

·

Published

2022-03-07

·

Updated

2023-08-02

·

CVE-2022-0384

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Video Conferencing with Zoom WordPress plugin versions prior to 3.8.17
Description The issue concerns a lack of authorization in the vczapi get wp users AJAX action, allowing any authenticated users, such as subscribers, to download the list of email addresses registered on the blog.
Recommendations For versions prior to 3.8.17, update to version 3.8.17 or later to resolve the issue. As a temporary workaround, consider restricting access to the vczapi get wp users AJAX action to minimize the risk of exploitation.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-0384

Affected Products

Video Conferencing With Zoom Wordpress Plugin