Authorization Bypass in Video Conferencing Plugin for WordPress
CVE-2026-6964

5.3MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
16 June 2026

What is CVE-2026-6964?

The Video Conferencing with Zoom plugin for WordPress has a significant security flaw that allows unauthorized users to bypass authentication. This vulnerability enables attackers to gain access to the site's Zoom SDK API key and generate a freshly-signed JWT (JSON Web Token) to join any Zoom meeting linked to that account without needing a legitimate invitation. It affects all versions up to and including 4.6.7, highlighting the critical need for users to update their plugins to ensure the security of their Zoom integrations.

Affected Version(s)

Video Conferencing with Zoom 0 <= 4.6.7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

andre chiape
.