What is CVE-2026-66641?
CVE-2026-66641 is a Contributor-level Stored Cross-Site Scripting (XSS) vulnerability in the Video Conferencing with Zoom plugin versions up to 4.6.8. This flaw could allow an authenticated attacker with Contributor privileges to execute arbitrary scripts in a victim's browser, making it critical to update the plugin to the latest available version.
Azərbaycanca: CVE-2026-66641, Video Conferencing with Zoom plaginin 4.6.8 və daha əvvəlki versiyalarında Contributor səviyyəli istifadəçilər tərəfindən icra edilə bilən Saxlanılan Cross-Site Scripting (XSS) zəifliyidir. Bu zəiflik təcavüzkara qurbanın brauzerində ixtiyari skript icra etməyə imkan verə bilər, buna görə plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What level of privileges does an attacker need to exploit CVE-2026-66641?
The attacker needs to be authenticated with Contributor-level privileges on the Video Conferencing with Zoom plugin.
What is the recommended action to protect against CVE-2026-66641?
It is recommended to update the Video Conferencing with Zoom plugin to the latest available version to protect against this Stored XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.