What the vulnerability does
01Description
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapi_encrypt_decrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.
Explanation of Vulnerability in Simple Terms
02Summary
A third-party video conferencing integration in j_3rk's product exposes limited sensitive information through network access. The vulnerability requires specific conditions to exploit and does not allow modification or disruption of service. Versions up to 4.2.1 are affected. Update to a version newer than 4.2.1 to remediate.
What an attacker can do
03Attacker Capabilities
Read limited sensitive information from the application over the network.
Potential impact on your site
04Site Impact
Sensitive data may be exposed to unauthenticated network-based attackers under specific conditions.
Conditions required to exploit
05Prerequisites
Network access and specific attack conditions; no authentication or user interaction required.
Key dates
06Disclosure timeline
July 26, 2023
CVE published
April 8, 2026
Record updated