CVE-2026-77008

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated users to overwrite them and repoint every online classroom, along with the shared secret those sessions are signed with, at infrastructure of their choosing.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-29 06:17

Updated : 2026-08-31 20:14


NVD link : CVE-2026-77008

Mitre link : CVE-2026-77008

CVE.ORG link : CVE-2026-77008


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control