CyberRota Analysis
AI-GeneratedThe HEL Online Classroom WordPress plugin versions up to 1.0.3 lacks proper authorization and authentication checks when saving settings, enabling unauthenticated users to modify configurations. This vulnerability allows attackers to redirect online classrooms and alter session signing secrets, potentially compromising user data and session integrity. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access and manipulation.
Original NVD Description
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated users to overwrite them and repoint every online classroom, along with the shared secret those sessions are signed with, at infrastructure of their choosing.