CVE 5.3 MEDIUM

eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams <= 1.5.6 - Unauthenticated Sensitive Information Exposure_CVE-2025-11760

5.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom SDK secret keys in client-side JavaScript within the meeting view template. This makes it possible for unauthenticated attackers to extract the sdk_secret value, which should remain server-side, compromising the security of the Zoom integration and allowing attackers to generate valid JWT signatures for unauthorized meeting access.

Basic Information

ID CVE-2025-11760
Source Wordfence
Published Oct 25, 2025 at 01:45

Affected Product

Vendor wpcenter
Product eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams
Version *
Affected Versions wpcenter eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.