Junglewise Threat Intelligence

CVE-2026-25427: DigitalME eRoom broken access control in Zoom Meetings & Webinar plugin

CVE-2026-25427 · Severity: medium · CVSS 5.4 · Published 2026-07-23

Vendors: StylemixThemes.

Executive brief

The eRoom plugin for WordPress, which integrates Zoom meetings and webinars into websites, contains a security flaw in its access control mechanisms. This vulnerability allows logged-in users with low-level 'Subscriber' permissions to perform actions they should not be authorized to do. This could potentially lead to unauthorized changes to meeting settings or disruptions to webinar operations.

Technical details

The eRoom plugin (versions 1.7.1 and below) for WordPress suffers from a broken access control vulnerability (CWE-862: Missing Authorization). The flaw exists because the plugin fails to properly validate user permissions or implement sufficient nonce checks on certain functions. An attacker authenticated with basic 'Subscriber' privileges can exploit this over the network to execute higher-privileged actions. While the specific impacted functions are not detailed in the advisory, the CVSS vector indicates a low impact on integrity and availability. As of the advisory date, no official patch has been confirmed.

Affected products

  • DigitalME (StylemixThemes) eRoom – Zoom Meetings & Webinar <= 1.7.1

Timeline

  • 2025-12-28: other: Vulnerability reported by researcher Nabil Irawan
  • 2026-07-22: advisory: Patchstack advisory published
  • 2026-07-23: disclosed: CVE published to NVD dataset

References