VYPR

Video Conferencing With Zoom

by WordPress

CVEs (2)

  • CVE-2026-1368HigFeb 18, 2026
    risk 0.49cvss 7.5epss 0.01

    The Video Conferencing with Zoom WordPress plugin before 4.6.6 contains an AJAX handler that has its nonce verification commented out, allowing unauthenticated attackers to generate valid Zoom SDK signatures for any meeting ID and retrieve the site's Zoom SDK key.

  • CVE-2026-6964MedJun 16, 2026
    risk 0.34cvss 5.3epss 0.00

    The Video Conferencing with Zoom plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.6.7. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…