CVE-2022-25614: WordPress eRoom plugin <= 1.3.7 - Cross-Site Request Forgery (CSRF) leading to Sync with Zoom Meetings vulnerability
Published Apr 11, 2022
·Updated
Cross-Site Request Forgery (CSRF) in StylemixThemes eRoom – Zoom Meetings & Webinar (WordPress plugin) <= 1.3.7 allows an attacker to Sync with Zoom Meetings.
Affected Software
1 affected component
StylemixThemes Eroom - Zoom Meetings \& Webinar Wordpress<=1.3.7
Remediation
Information
Update to 1.3.8 or higher version.
Event History
Apr 11, 2022
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2022-25614.
2
What is the severity of CVE-2022-25614?
The severity of CVE-2022-25614 is medium.
3
What is affected by CVE-2022-25614?
StylemixThemes eRoom - Zoom Meetings & Webinar (WordPress plugin) version 1.3.7 and below is affected by CVE-2022-25614.
4
How can an attacker exploit the vulnerability?
An attacker can exploit CVE-2022-25614 by conducting Cross-Site Request Forgery (CSRF) attacks to perform actions on behalf of authenticated users.
5
Is there a patch or update available for CVE-2022-25614?
Yes, a patch or update is available for CVE-2022-25614. It is recommended to update the StylemixThemes eRoom - Zoom Meetings & Webinar plugin to version 1.3.8 or later.