PT-2026-57122 · WordPress · Goodmeet

·

CVE-2026-6440

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference versions prior to 1.1.9
Description Cross-Site Request Forgery (CSRF) occurs due to missing nonce verification in the reset credential() function, which handles the wp ajax goodmeet reset google meet credential AJAX action. Although the function checks for the manage options capability, the lack of a nonce allows unauthenticated attackers to trick a site administrator into clicking a malicious link. This action resets and deletes the stored Google Meet API credentials goodmeet google credentials and OAuth tokens goodmeet google token, resulting in the disablement of the Google Meet integration on the site.
Recommendations Update to a version newer than 1.1.8.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6440

Affected Products

Goodmeet