Description
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-44573 | The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password. |
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Video Conferencing with Zoom <= 4.2.1 - Sensitive Information Exposure | |
| Weaknesses | CWE-321 |
Wed, 05 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-08T17:18:11.535Z
Reserved: 2023-07-25T15:30:56.265Z
Link: CVE-2023-3947
Updated: 2024-08-02T07:08:50.679Z
Status : Modified
Published: 2023-07-26T04:15:11.117
Modified: 2026-04-08T19:18:27.550
Link: CVE-2023-3947
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD