CVE-2026-77007
—Unauthenticated Settings Disclosure in HEL Online Classroom WordPress Plugin
CVE-2026-77007 is an information disclosure flaw (CWE-200) in the HEL Online Classroom: AI-powered Online Classrooms WordPress plugin, which performs no authorization check on one of its REST API routes. Any unauthenticated remote attacker can call that route over the network and retrieve the plugin's stored settings. The exposed settings include the shared secret used to sign API requests to the connected BigBlueButton server, which an attacker could reuse to forge validly signed requests to that server. Only WordPress sites running the plugin in versions through 1.0.3 — typically those using it to connect to a BigBlueButton server — are affected. No public proof-of-concept or in-the-wild exploitation is currently known; EPSS estimates only about a 0.3% probability of exploitation within 30 days, and the issue is not in CISA's KEV catalog.
What to do: Update the plugin to the first available release after 1.0.3 (the exact fixed version is not specified in the available data), or deactivate the plugin until a patched version is installed. Because the BigBlueButton shared secret was retrievable by unauthenticated users, rotate that secret after patching and review web logs for unauthenticated requests to the plugin's REST routes. As an interim mitigation, block unauthenticated access to the plugin's REST endpoints, for example via a WAF rule or a plugin/mu-plugin that filters REST API requests.
| HEL Online Classroom: AI-powered Online Classrooms (WordPress plugin) | all versions through and including 1.0.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to the connected BigBlueButton server.
- Ecosystems
- WordPress
- Weakness
- CWE-200
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.