The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
References
Configurations
No configuration.
History
18 Feb 2026, 14:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-287 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
18 Feb 2026, 06:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-18 06:16
Updated : 2026-02-18 17:51
NVD link : CVE-2026-1368
Mitre link : CVE-2026-1368
CVE.ORG link : CVE-2026-1368
JSON object : View
Products Affected
No product.
CWE
CWE-287
Improper Authentication
