Weak configuration vulnerability in Video Conferencing with Zoom 4.2.1

The Video Conferencing with Zoom plugin, which allows users to use the Zoom online service in their WordPress websites, is vulnerable to a security issue. In versions up to and including 4.2.1, the plugin uses a hardcoded encryption key for the ‘vczapi_encrypt_decrypt’ function, which could be used by an unauthenticated attacker to decrypt the meeting ID and password. This could potentially expose them to malicious activity. It is important to update to the latest version of the plugin to ensure your security.

Detected in:

Video Conferencing with Zoom fixed vulnerable versions: >= * <= 4.2.1

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.