Zoom WordPress plugin < 4.6.6 contains a broken authentication caused by disabled nonce verification in an AJAX handler, letting unauthenticated attackers generate valid Zoom SDK signatures and retrieve the Zoom SDK key.
id: CVE-2026-1368
info:
name: Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Sign
...