The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
History

Wed, 18 Feb 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
Title Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-02-18T06:00:09.953Z

Reserved: 2026-01-23T13:19:23.260Z

Link: CVE-2026-1368

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-18T06:16:34.327

Modified: 2026-02-18T06:16:34.327

Link: CVE-2026-1368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.