The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 18 Feb 2026 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-287
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Feb 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Video Conferencing With Zoom Project
Video Conferencing With Zoom Project video Conferencing With Zoom
Wordpress
Wordpress wordpress
Vendors & Products Video Conferencing With Zoom Project
Video Conferencing With Zoom Project video Conferencing With Zoom
Wordpress
Wordpress wordpress

Wed, 18 Feb 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
Title Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-02-18T14:02:28.900Z

Reserved: 2026-01-23T13:19:23.260Z

Link: CVE-2026-1368

cve-icon Vulnrichment

Updated: 2026-02-18T14:02:24.328Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-18T06:16:34.327

Modified: 2026-02-18T17:51:53.510

Link: CVE-2026-1368

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-18T10:32:42Z

Weaknesses