Junglewise Threat Intelligence

CVE-2026-39653: Deepen Bajracharya Video Conferencing with Zoom missing authorization

CVE-2026-39653 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Executive brief

A vulnerability exists in the 'Video Conferencing with Zoom' WordPress plugin, which is used to integrate Zoom meetings directly into websites. An authenticated user with low-level permissions could exploit incorrectly configured access controls to perform unauthorized actions. This could lead to minor disruptions in service or unauthorized changes to meeting configurations.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Deepen Bajracharya Video Conferencing with Zoom plugin (video-conferencing-with-zoom-api) for WordPress. The flaw is located within the plugin's access control logic, where security levels are incorrectly configured or checked. An attacker authenticated with low-level privileges (such as a Subscriber) can exploit this over the network to execute functions or access data they are not authorized to reach. The vulnerability affects all versions up to and including 4.6.6; it is addressed in version 4.6.7.

Affected products

  • Deepen Bajracharya Video Conferencing with Zoom <= 4.6.6

Timeline

  • 2026-01-16: other: Reported by Nabil Irawan
  • 2026-02-15: advisory: Patchstack advisory published
  • 2026-04-08: disclosed: CVE published

References