Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation
CVE-2026-1368
Verified
Description
Zoom WordPress plugin < 4.6.6 contains a broken authentication caused by disabled nonce verification in an AJAX handler, letting unauthenticated attackers generate valid Zoom SDK signatures and retrieve the Zoom SDK key.
Severity
High
CVSS Score
7.5
Exploit Probability
1%
Published Date
April 29, 2026
Template Author
0x_akoko
CVE-2026-1368.yaml
7.5Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVE ID:
cve-2026-1368
CWE ID:
cwe-862
Remediation Steps
Update to version 4.6.6 or later.