Sensitive Information Exposure in Video Conferencing with Zoom WordPress Plugin

Sensitive Information Exposure in Video Conferencing with Zoom WordPress Plugin

CVE-2023-3947 · MEDIUM Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.

Learn more about our Wordpress Pen Testing.