Authorization Bypass in Video Conferencing Plugin for WordPress
CVE-2026-6964
5.3MEDIUM
What is CVE-2026-6964?
The Video Conferencing with Zoom plugin for WordPress has a significant security flaw that allows unauthorized users to bypass authentication. This vulnerability enables attackers to gain access to the site's Zoom SDK API key and generate a freshly-signed JWT (JSON Web Token) to join any Zoom meeting linked to that account without needing a legitimate invitation. It affects all versions up to and including 4.6.7, highlighting the critical need for users to update their plugins to ensure the security of their Zoom integrations.
Affected Version(s)
Video Conferencing with Zoom 0 <= 4.6.7