Back

MEDIUM

Video Conferencing with Zoom <= 4.4.5 - Sensitive Information Exposure

Published Apr 9, 2024

Description

The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all users on a site.

Affected products

Remediation

No remediation recorded yet.

References (3)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner Wordfence
Published Apr 9, 2024
Updated Apr 8, 2026
Reserved Feb 29, 2024

CISA Vulnrichment

Updated Jul 16, 2024

NVD

Status Deferred
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner Wordfence
Published Apr 9, 2024
Updated Apr 8, 2026

GitHub

No data