CVE-2022-4578: Video Conferencing with Zoom < 4.0.10 - Contributor+ Stored XSS
The Video Conferencing with Zoom WordPress plugin before 4.0.10 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-4578.
What is the severity of CVE-2022-4578?
The severity of CVE-2022-4578 is medium with a severity value of 5.4.
What is affected by CVE-2022-4578?
The Video Conferencing with Zoom WordPress plugin before version 4.0.10 is affected by CVE-2022-4578.
What is the impact of CVE-2022-4578?
CVE-2022-4578 allows users with a role as low as contributor to perform Stored Cross-Site Scripting attacks.
How can I fix CVE-2022-4578?
To fix CVE-2022-4578, update the Video Conferencing with Zoom WordPress plugin to version 4.0.10 or higher.