PT-2024-24825 · WordPress · Eroom – Zoom Meetings & Webinar

Krzysztof Zając

·

Published

2024-05-02

·

Updated

2024-05-02

·

CVE-2024-3275

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions The eRoom – Zoom Meetings & Webinars plugin for WordPress versions up to, and including, 1.4.18
Description The issue allows authenticated attackers with subscriber access or higher to obtain post excerpts, including those of draft and pending posts, via the search posts function. This enables them to expose sensitive information.
Recommendations For versions up to, and including, 1.4.18, update to a version higher than 1.4.18 to resolve the issue. As a temporary workaround, consider restricting access to the search posts function to minimize the risk of exploitation.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2024-3275

Affected Products

Eroom – Zoom Meetings & Webinar