Skip to content
Noroxi

Roomcloud

roomcloud · plugin

Known security vulnerabilities for Roomcloud. Find out in seconds which version runs on your site with WP Lens.

1 known vulnerabilities

latest May 29, 2015

Listed on wordpress.org · latest 2.0.32 · last updated Apr 3, 2026 · 300+ installs

wordpress.org status checked on Oct 2, 2026

Vulnerabilities

  • CVE-2015-3904

    Multiple cross-site scripting (XSS) vulnerabilities in roomcloud.php in the Roomcloud plugin before 1.3 for WordPress allow remote attackers

    Medium 4.3

The access label is read from the record's own text (e.g. “subscriber+”: subscriber and above). When the text names no role, CVSS decides between “login required” and “high privilege”; no role name is invented. “Needs a click”: the attack depends on a logged-in user following a link (CSRF, reflected XSS).

← Back to directory