AJAX Handler Vulnerability in Video Conferencing Plugin for WordPress by Zoom
CVE-2026-1368
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 18 February 2026
Badges
What is CVE-2026-1368?
The Video Conferencing with Zoom plugin for WordPress prior to version 4.6.6 contains a significant security issue in its AJAX handler. The nonce verification mechanism, which is crucial for preventing unauthorized access, has been commented out, exposing a critical vulnerability. This flaw allows unauthenticated attackers to craft valid Zoom SDK signatures for any meeting ID, consequently gaining access to sensitive information such as the site's Zoom SDK key. This creates potential risks for unauthorized use of the Zoom service and jeopardizes the security of online meetings hosted through the plugin.
Affected Version(s)
Video Conferencing with Zoom 0 < 4.6.6
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved