CVE-2026-1368

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
Configurations

No configuration.

History

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) El plugin de WordPress Video Conferencing con Zoom anterior a la versión 4.6.6 contiene un manejador AJAX que tiene su verificación de nonce comentada, lo que permite a atacantes no autenticados generar firmas válidas del SDK de Zoom para cualquier ID de reunión y recuperar la clave del SDK de Zoom del sitio.

18 Feb 2026, 14:16

Type Values Removed Values Added
CWE CWE-287
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

18 Feb 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-18 06:16

Updated : 2026-06-17 10:15


NVD link : CVE-2026-1368

Mitre link : CVE-2026-1368

CVE.ORG link : CVE-2026-1368


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication