MEDIUM
Video Conferencing with Zoom <= 4.4.5 - Sensitive Information Exposure
Published Apr 9, 2024
4.3
MEDIUMCVSS 3.1
EPSS 0.46%
Description
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all users on a site.
Affected products
-
Affected
- ≥ 0, ≤ 4.4.5
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| J 3rk | Video Conferencing with Zoom | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-27001 Advisory
- https://plugins.trac.wordpress.org/changeset/3054964/video-conferencing-with-zoom-api/trunk?contextall=1&old=3048839&old_path=%2Fvideo-conferencing-with-zoom-api%2Ftrunk
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0966057b-8a3c-4d3c-84cb-cf36f1d97922?source=cve
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Apr 9, 2024
Updated Apr 8, 2026
Reserved Feb 29, 2024
Link CVE-2024-2033
CISA Vulnrichment
Updated Jul 16, 2024
Red Hat
No data
GitHub
No data