CVE-2025-11760
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-10-25

Last updated on: 2025-10-27

Assigner: Wordfence

Description
The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom SDK secret keys in client-side JavaScript within the meeting view template. This makes it possible for unauthenticated attackers to extract the sdk_secret value, which should remain server-side, compromising the security of the Zoom integration and allowing attackers to generate valid JWT signatures for unauthorized meeting access.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-10-25
Last Modified
2025-10-27
Generated
2026-05-07
AI Q&A
2025-10-25
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
wordfence eroom_zoom_meetings_webinar 1.5.6
wordfence eroom_zoom_meetings_webinar 1.5.7
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability exists in the eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams for WordPress, versions up to 1.5.6. It exposes Zoom SDK secret keys in client-side JavaScript within the meeting view template. Because these secret keys are visible to anyone, unauthenticated attackers can extract the sdk_secret value, which should be kept server-side. This exposure compromises the security of the Zoom integration and allows attackers to generate valid JWT signatures to gain unauthorized access to meetings.


How can this vulnerability impact me? :

The vulnerability can allow unauthenticated attackers to obtain secret keys and generate valid JWT signatures, leading to unauthorized access to meetings. This compromises the confidentiality of meetings, potentially exposing sensitive information to unauthorized parties.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart