CVE-2026-1368
Last modified
CVE-2026-1368 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1368?
How severe is CVE-2026-1368?
How do I fix CVE-2026-1368?
Are you affected by CVE-2026-1368?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
