Show filters
182 Total Results
Displaying 31-40 of 182
Sort by:
Attacker Value
Unknown

CVE-2024-2189

Disclosure Date: May 21, 2024 (last updated May 21, 2024)
The Social Icons Widget & Block by WPZOOM WordPress plugin before 4.2.18 does not sanitise and escape some of its Widget settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
0
Attacker Value
Unknown

CVE-2024-27244

Disclosure Date: May 15, 2024 (last updated May 16, 2024)
Insufficient verification of data authenticity in the installer for Zoom Workplace VDI App for Windows may allow an authenticated user to conduct an escalation of privilege via local access.
0
Attacker Value
Unknown

CVE-2024-4370

Disclosure Date: May 15, 2024 (last updated February 06, 2025)
The WPZOOM Addons for Elementor (Templates, Widgets) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widget Image Box in all versions up to, and including, 1.1.36 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.
Attacker Value
Unknown

CVE-2024-3275

Disclosure Date: May 02, 2024 (last updated January 05, 2025)
The eRoom – Zoom Meetings & Webinars plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.4.18 via the search_posts function. This makes it possible for authenticated attackers, with subscriber access and higher, to obtain post excerpts including those of draft and pending posts.
0
Attacker Value
Unknown

CVE-2024-33584

Disclosure Date: April 29, 2024 (last updated April 29, 2024)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Deepen Bajracharya Video Conferencing with Zoom.This issue affects Video Conferencing with Zoom: from n/a through 4.4.4.
0
Attacker Value
Unknown

CVE-2024-33539

Disclosure Date: April 29, 2024 (last updated February 04, 2025)
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPZOOM WPZOOM Addons for Elementor (Templates, Widgets) allows Stored XSS.This issue affects WPZOOM Addons for Elementor (Templates, Widgets): from n/a through 1.1.35.
Attacker Value
Unknown

CVE-2024-32454

Disclosure Date: April 15, 2024 (last updated April 29, 2024)
Server-Side Request Forgery (SSRF) vulnerability in Wappointment Appointment Bookings for Zoom GoogleMeet and more – Wappointment.This issue affects Appointment Bookings for Zoom GoogleMeet and more – Wappointment: from n/a through 2.6.0.
0
Attacker Value
Unknown

CVE-2024-3662

Disclosure Date: April 13, 2024 (last updated April 13, 2024)
The WPZOOM Social Feed Widget & Block plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the wpzoom_instagram_clear_data() function in all versions up to, and including, 2.1.13. This makes it possible for authenticated attackers, with subscriber-level access and above, to delete all Instagram images installed on the site.
0
Attacker Value
Unknown

CVE-2024-2033

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
The Video Conferencing with Zoom plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.4.5 via the get_assign_host_id AJAX action. This makes it possible for authenticated attackers, with subscriber access or higher, to enumerate usernames, emails and IDs of all users on a site.
0
Attacker Value
Unknown

CVE-2024-27247

Disclosure Date: April 09, 2024 (last updated April 10, 2024)
Improper privilege management in the installer for Zoom Desktop Client for macOS before version 5.17.10 may allow a privileged user to conduct an escalation of privilege via local access.
0