CVE-2023-3947: Video Conferencing with Zoom <= 4.2.1 - Sensitive Information Exposure
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure due to hardcoded encryption key on the 'vczapiencryptdecrypt' function in versions up to, and including, 4.2.1. This makes it possible for unauthenticated attackers to decrypt and view the meeting id and password.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3947?
CVE-2023-3947 has been classified as a high-severity vulnerability due to its potential for sensitive information exposure.
How do I fix CVE-2023-3947?
To mitigate CVE-2023-3947, update the Video Conferencing with Zoom plugin to version 4.2.2 or later.
What systems are affected by CVE-2023-3947?
CVE-2023-3947 affects the Video Conferencing with Zoom plugin for WordPress versions up to and including 4.2.1.
What type of vulnerability is CVE-2023-3947?
CVE-2023-3947 is a sensitive information exposure vulnerability resulting from a hardcoded encryption key.
Who can exploit CVE-2023-3947?
CVE-2023-3947 can be exploited by unauthenticated attackers, allowing them to decrypt and view sensitive meeting information.