Junglewise Threat Intelligence

CVE-2026-66641: WordPress Video Conferencing with Zoom XSS in contributor input

CVE-2026-66641 · Severity: medium · CVSS 6.5 · Published 2026-08-18

Vendors: Wordpress.

Executive brief

The Video Conferencing with Zoom WordPress plugin allows users to add video conferencing to their websites. A cross-site scripting (XSS) vulnerability in versions 4.6.9 and earlier lets attackers with contributor-level access inject malicious scripts that could steal visitor data or hijack user accounts. A privileged user would need to interact with an attacker's crafted input (e.g., click a malicious link) for the attack to succeed.

Technical details

This is a reflected/stored cross-site scripting (XSS) vulnerability in the Video Conferencing with Zoom WordPress plugin affecting versions through 4.6.9. The vulnerability exists in contributor-level functionality where user input is not properly sanitized or escaped before being rendered. An attacker with contributor privileges can craft malicious input containing JavaScript code; when a privileged user (administrator or higher) interacts with the malicious content, the script executes in their browser context. This could lead to account hijacking, session theft, or modification of site content. The vulnerability has been patched in version 4.6.10 and later.

Affected products

  • WordPress Video Conferencing with Zoom <=4.6.9

Timeline

  • 2026-07-09: disclosed: Reported by Ananda Dhakal (Patchstack)
  • 2026-08-18: advisory: Published by Patchstack
  • 2026-08-18: patched: Version 4.6.10 available

References