PT-2025-43694 · WordPress+1 · Eroom+1

Rafshanzani Suhada

·

Published

2025-10-25

·

Updated

2025-10-25

·

CVE-2025-11760

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams versions through 1.5.6
Description The eRoom plugin for WordPress exposes Zoom SDK secret keys in client-side JavaScript within the meeting view template. This allows unauthenticated attackers to extract the sdk secret value, which should be server-side. Compromising the Zoom integration enables attackers to generate valid JWT signatures for unauthorized meeting access.
Recommendations Versions prior to and including 1.5.6 should be updated to a newer version that addresses this issue.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-11760

Affected Products

Zoom
Eroom