AJAX Handler Vulnerability in Video Conferencing Plugin for WordPress by Zoom
CVE-2026-1368

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
18 February 2026

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2026-1368?

The Video Conferencing with Zoom plugin for WordPress prior to version 4.6.6 contains a significant security issue in its AJAX handler. The nonce verification mechanism, which is crucial for preventing unauthorized access, has been commented out, exposing a critical vulnerability. This flaw allows unauthenticated attackers to craft valid Zoom SDK signatures for any meeting ID, consequently gaining access to sensitive information such as the site's Zoom SDK key. This creates potential risks for unauthorized use of the Zoom service and jeopardizes the security of online meetings hosted through the plugin.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Video Conferencing with Zoom 0 < 4.6.6

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

yiğit ibrahim sağlam
WPScan
.