Executive brief
The eRoom plugin for WordPress, which integrates Zoom meetings and webinars into websites, contains a security flaw that could allow users with 'Contributor' level access to interfere with the site's database. An attacker could exploit this to steal sensitive information or disrupt site operations. This is particularly concerning for sites that allow multiple users to create or edit content.
Technical details
A SQL injection vulnerability exists in the eRoom - Zoom Meetings & Webinar plugin for WordPress (versions <= 1.7.1) due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability requires 'Contributor' level authentication (PR:L) and can be exploited over the network without user interaction. Successful exploitation allows an attacker to directly interact with the underlying database, potentially leading to unauthorized data extraction or limited service disruption. As of the advisory date, no official patch has been confirmed.
Affected products
- DigitalME (StylemixThemes) eRoom - Zoom Meetings & Webinar <= 1.7.1
Timeline
- 2025-12-30: disclosed: Reported by Trương Hữu Phúc to Patchstack
- 2026-07-23: advisory: NVD and Patchstack published the vulnerability details