Impact
The vulnerability is an Insertion of Sensitive Information Into Sent Data flaw in the WordPress Video Conferencing with Zoom plugin. This flaw allows attackers to retrieve embedded sensitive data from the plugin, leading to unauthorized disclosure of confidential information.
Affected Systems
The Deepen Bajracharya Video Conferencing with Zoom plugin versions up to and including 4.6.10 are affected. All installations of this plugin that have not been updated to a later release are at risk.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is not available, making it unclear how frequently exploits have been observed, but the vulnerability is not listed in CISA KEV. Attack vectors are not explicitly documented in the advisory; inferred that exploitation may require access to the plugin’s functionality, possibly via a web interface or administrative actions.
OpenCVE Enrichment