First published: Mon Jan 16 2023(Updated: )
The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zoom Video Conferencing | <4.0.10 | |
<4.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2022-4578.
The severity of CVE-2022-4578 is medium with a severity value of 5.4.
The Video Conferencing with Zoom WordPress plugin before version 4.0.10 is affected by CVE-2022-4578.
CVE-2022-4578 allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
To fix CVE-2022-4578, update the Video Conferencing with Zoom WordPress plugin to version 4.0.10 or higher.