CVE-2026-1368

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
Configurations

No configuration.

History

No history.

Information

Published : 2026-02-18 06:16

Updated : 2026-02-18 17:51


NVD link : CVE-2026-1368

Mitre link : CVE-2026-1368

CVE.ORG link : CVE-2026-1368


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication