The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to the connected BigBlueButton server.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-29 06:17
Updated : 2026-08-31 20:14
NVD link : CVE-2026-77007
Mitre link : CVE-2026-77007
CVE.ORG link : CVE-2026-77007
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
