Junglewise Threat Intelligence

CVE-2026-6440: Sovlix GoodMeet CSRF in reset_credential function

CVE-2026-6440 · Severity: medium · CVSS 4.3 · Published 2026-07-10

Executive brief

The GoodMeet plugin for WordPress, which integrates Google Meet for webinars and video conferences, contains a security flaw that could allow an attacker to disable the integration. By tricking a site administrator into clicking a malicious link, an attacker can force the website to delete its Google Meet API credentials and access tokens. This would disrupt any scheduled meetings or webinar functionality relying on the plugin until the administrator manually reconfigures the connection.

Technical details

The GoodMeet plugin for WordPress is vulnerable to Cross-Site Request Forgery (CSRF) due to missing nonce verification in the reset_credential() function. This function handles the wp_ajax_goodmeet_reset_google_meet_credential AJAX action. Although the function checks for the 'manage_options' capability, the lack of a security nonce allows an unauthenticated attacker to craft a malicious request. If a logged-in administrator interacts with this request (e.g., by clicking a link), the plugin will delete the stored 'goodmeet_google_credentials' and 'goodmeet_google_token' from the database. This effectively disconnects the site from the Google Meet API. The issue is fixed in versions following 1.1.8.

Affected products

  • sovlix GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference up to and including 1.1.8

Timeline

  • 2026-07-10: disclosed
  • 2026-07-10: advisory

References