CVE-2026-103335
Received Received - Intake

Video Conferencing with Zoom API Sensitive Data Exposure

Vulnerability report for CVE-2026-103335, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Patchstack

Description

Insertion of Sensitive Information Into Sent Data vulnerability in Deepen Bajracharya Video Conferencing with Zoom video-conferencing-with-zoom-api allows Retrieve Embedded Sensitive Data.This issue affects Video Conferencing with Zoom: from n/a through 4.6.10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
deepen_bajracharya video_conferencing_with_zoom to 4.6.10 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-201 The code transmits data to another actor, but a portion of the data includes sensitive information that should not be accessible to that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves the Video Conferencing with Zoom WordPress plugin versions 4.6.10 and earlier exposing sensitive data such as passwords, emails, or payment details to unauthorized parties. It allows retrieval of embedded sensitive information due to improper handling of data transmission.

Detection Guidance

To detect this vulnerability, check if the Video Conferencing with Zoom plugin is installed and verify its version. If the version is 4.6.10 or earlier, the system is vulnerable. Use commands like 'wp plugin list' for WordPress sites or inspect plugin files for version details.

Impact Analysis

The impact includes potential exposure of private information like passwords, emails, or payment details to attackers. While the severity is low, unauthorized access to such data could lead to identity theft, financial loss, or further compromise of user accounts.

Mitigation Strategies

Immediately update the Video Conferencing with Zoom plugin to version 4.6.11 or later. If updating is not possible, seek assistance from a hosting provider or web developer. Enable auto-updates for vulnerable plugins if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-103335. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart