Loading market data...
← Back to CVE feed

CVE-2026-77008

MEDIUM CVSS 6.5 View on NVD ↗

Description

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated users to overwrite them and repoint every online classroom, along with the shared secret those sessions are signed with, at infrastructure of their choosing.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Published: Aug 29, 2026 06:17 UTC Modified: Aug 30, 2026 01:20 UTC