CVE Database
/

CVE-2026-1368

Back to search

CVE-2026-1368

Published: Feb 18, 2026

Modified: Feb 18, 2026

PUBLISHED

Description

The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.

VendorProductVersions

Unknown

Video Conferencing with Zoom

affected
0 - < 4.6.6

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now