CVE-2026-77007
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to the connected BigBlueButton server.
- Published Aug 29, 2026
- CVSS 7.5 high
- 0.4% chance of exploitation in the next 30 days (EPSS)