PT-2025-43694 · WordPress+1 · Eroom+1
Rafshanzani Suhada
·
Published
2025-10-25
·
Updated
2025-10-25
·
CVE-2025-11760
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams versions through 1.5.6
Description
The eRoom plugin for WordPress exposes Zoom SDK secret keys in client-side JavaScript within the meeting view template. This allows unauthenticated attackers to extract the
sdk secret value, which should be server-side. Compromising the Zoom integration enables attackers to generate valid JWT signatures for unauthorized meeting access.Recommendations
Versions prior to and including 1.5.6 should be updated to a newer version that addresses this issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Zoom
Eroom