CVE-2026-6440 Details
Description
The GoodMeet – Google Meet Integration for Webinar, Meeting & Video Conference plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to and including 1.1.8. This is due to a missing nonce verification in the reset_credential() function, which handles the wp_ajax_goodmeet_reset_google_meet_credential AJAX action. While the function does verify the user's capability (manage_options), it does not validate a nonce, making it susceptible to CSRF attacks. This makes it possible for unauthenticated attackers to trick a site administrator into clicking a malicious link that will reset (delete) the plugin's stored Google Meet API credentials (goodmeet_google_credentials) and OAuth tokens (goodmeet_google_token), effectively disabling the Google Meet integration on the site.
A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the GoodMeet WordPress plugin, specifically in versions through 1.1.8. The issue arises from a lack of nonce verification in the 'reset_credential' function, which manages the 'wp_ajax_goodmeet_reset_google_meet_credential' AJAX action. While the function checks the user's capability to manage options, it fails to validate a nonce, leaving it open to CSRF attacks. This vulnerability allows unauthenticated attackers to deceive site administrators into clicking a malicious link that resets the plugin's Google Meet API credentials and OAuth tokens, thereby disabling the Google Meet integration on the site.
Users are advised to update the GoodMeet WordPress plugin to version 1.1.9 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 10, 2026CISA-ADP
Assessed Jul 10, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SOVLIX GoodMeet | <= 1.1.8 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 10, 2026 | CVE Modified | CISA-ADP |
| Jul 10, 2026 | New CVE Received | [email protected] |
Volerion