Executive brief
A vulnerability exists in the 'Video Conferencing with Zoom' WordPress plugin, which is used to integrate Zoom meetings directly into websites. An authenticated user with low-level permissions could exploit incorrectly configured access controls to perform unauthorized actions. This could lead to minor disruptions in service or unauthorized changes to meeting configurations.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Deepen Bajracharya Video Conferencing with Zoom plugin (video-conferencing-with-zoom-api) for WordPress. The flaw is located within the plugin's access control logic, where security levels are incorrectly configured or checked. An attacker authenticated with low-level privileges (such as a Subscriber) can exploit this over the network to execute functions or access data they are not authorized to reach. The vulnerability affects all versions up to and including 4.6.6; it is addressed in version 4.6.7.
Affected products
- Deepen Bajracharya Video Conferencing with Zoom <= 4.6.6
Timeline
- 2026-01-16: other: Reported by Nabil Irawan
- 2026-02-15: advisory: Patchstack advisory published
- 2026-04-08: disclosed: CVE published