SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77010

MEDIUM · CVSS 6.5 EPSS 0.16%

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The HEL Online Classroom WordPress plugin versions up to 1.0.3 lacks proper authorization checks on its REST API routes, enabling unauthenticated users to generate signed meeting join links for any classroom, even those secured by access codes. This vulnerability allows unauthorized individuals to join classrooms with moderator privileges, potentially compromising sensitive educational sessions. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-77010
Severity
MEDIUM
CVSS
6.5
EPSS
0.16%
WordPress

Original NVD Description

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class access code, allowing unauthenticated users to obtain a signed meeting join link for any classroom, including one protected by an access code, and to join it with moderator privileges.