---
id: CVE-2025-11760
title: >-
  The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams
  plugin for WordPress is vulnerable to exposure of sensitive information in all
  versions up to, and including, 1.5.6
summary: >-
  The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams
  plugin for WordPress is vulnerable to exposure of sensitive information in all
  versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom
  SDK …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'
cwe:
  - CWE-200
published: '2025-10-25'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-11760'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/eroom-zoom-meetings-webinar/tags/1.5.6/templates/single/meeting_view.php#L173
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&new=3379064%40eroom-zoom-meetings-webinar%2Ftrunk&old=3375935%40eroom-zoom-meetings-webinar%2Ftrunk&sfp_email=&sfph_mail=#file4
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/0baaa6b7-3884-465e-bae3-46edab6312d4?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00314
epssPercentile: 0.22331
ingestedAt: '2026-10-08T11:31:27.577Z'
---

## Overview

The eRoom – Webinar & Meeting Plugin for Zoom, Google Meet, Microsoft Teams plugin for WordPress is vulnerable to exposure of sensitive information in all versions up to, and including, 1.5.6. This is due to the plugin exposing Zoom SDK secret keys in client-side JavaScript within the meeting view template. This makes it possible for unauthenticated attackers to extract the sdk_secret value, which should remain server-side, compromising the security of the Zoom integration and allowing attackers to generate valid JWT signatures for unauthorized meeting access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
