Unprotected API in HEL Online Classroom Plugin for WordPress
CVE-2026-77007
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 August 2026
Badges
What is CVE-2026-77007?
The HEL Online Classroom plugin for WordPress, specifically version 1.0.3, is susceptible to a critical security vulnerability that lacks proper authorization checks on a REST API route. This oversight enables unauthenticated users to access sensitive configuration settings, including a shared secret utilized for signing API requests to the connected BigBlueButton server. This flaw poses a significant risk by allowing potential intruders to exploit these settings, potentially leading to unauthorized access and control over the online classroom environment.
Affected Version(s)
HEL Online Classroom: AI-powered Online Classrooms 0 <= 1.0.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.