Medium severity4.3NVD Advisory· Published Mar 7, 2022· Updated Jun 17, 2026
CVE-2022-0384
CVE-2022-0384
Description
The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:imdpen:video_conferencing_with_zoom:*:*:*:*:*:wordpress:*:*Range: <3.8.17
(expand)+ 1 more
- (no CPE)
- (no CPE)range: <3.8.17
Patches
Vulnerability mechanics
References
2- plugins.trac.wordpress.org/changeset/2671219nvdPatchThird Party Advisory
- wpscan.com/vulnerability/91c44c45-994b-4aed-b9f9-7db45924eeb4nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.