cve/2022/CVE-2022-0384.md
2024-06-18 02:51:15 +02:00

815 B

CVE-2022-0384

Description

The Video Conferencing with Zoom WordPress plugin before 3.8.17 does not have authorisation in its vczapi_get_wp_users AJAX action, allowing any authenticated users, such as subscriber to download the list of email addresses registered on the blog

POC

Reference

Github

No PoCs found on GitHub currently.