PoC Index

CVE-2026-77007

HIGH 7.5EPSS 0.3%

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to the connected BigBlueButton server.

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS
0.26% chance of exploitation in the next 30 days, 17th percentile
Published
2026-08-29
Updated
2026-08-30

Proof-of-concept exploits (1)

References

Related