4.3
CVSSv3

CVE-2022-0384

Published: 07/03/2022 Updated: 02/08/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

The Video Conferencing with Zoom WordPress plugin prior to 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imdpen video conferencing with zoom