Description
Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
Published: 2026-10-10
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Unauthorized access due to broken authentication
Action: Immediate Patch
AI Analysis

Impact

The WordPress eRoom plugin contains an unauthenticated broken authentication flaw that allows an attacker to bypass login controls, potentially gaining unauthorized access to sensitive administrative functions such as account management, meeting scheduling, and configuration settings. The weakness stems from improper enforcement of authentication checks and is classified as CWE-288. An attacker could exploit this flaw without prior credentials, enabling them to read, modify, or delete content and compromise user data or service availability.

Affected Systems

The vulnerability affects DigitalME’s eRoom plugin for WordPress, versions 1.7.1 and earlier. Users running any of these versions on their WordPress installations are exposed to the authentication bypass unless upgraded to a newer release.

Risk and Exploitability

The CVSS base score of 7.3 indicates a moderate to high severity level. While the EPSS score is not available, the lack of a KEV listing suggests that this vulnerability has not yet been widely exploited publicly, but it remains a serious threat given its authentication bypass nature. Attackers could discover the flaw through web reconnaissance or administrative interfaces, and exploitation requires no special privileges or advanced skills, so the risk is significant for any site that deploys the vulnerable plugin.

Generated by OpenCVE AI on October 10, 2026 at 21:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the eRoom plugin to the latest supported version (≥1.7.2) to eliminate the authentication bypass flaw.
  • If an update is not immediately feasible, disable or remove the eRoom plugin from the WordPress installation to block the attack surface.
  • Apply the principle of least privilege by restricting administrative access to known IP addresses and enforce HTTPS for all admin traffic.

Generated by OpenCVE AI on October 10, 2026 at 21:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in eRoom <= 1.7.1 versions.
Title WordPress eRoom plugin <= 1.7.1 - Broken Authentication vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T19:35:35.694Z

Reserved: 2026-07-13T06:14:33.110Z

Link: CVE-2026-62038

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T20:16:40.010

Modified: 2026-10-10T20:16:40.010

Link: CVE-2026-62038

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T21:15:08Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel