SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77008

MEDIUM · CVSS 6.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The HEL Online Classroom WordPress plugin versions up to 1.0.3 lacks proper authorization and authentication checks when saving settings, enabling unauthenticated users to modify configurations. This vulnerability allows attackers to redirect online classrooms and alter session signing secrets, potentially compromising user data and session integrity. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access and manipulation.

CVE
CVE-2026-77008
Severity
MEDIUM
CVSS
6.5
EPSS
0.25%
WordPress

Original NVD Description

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated users to overwrite them and repoint every online classroom, along with the shared secret those sessions are signed with, at infrastructure of their choosing.