---
id: CVE-2026-77007
title: >-
  The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin
  through 1.0.3 does not perform any authorisation check on one of its REST API
  routes, allowing unauthenticated users to retrieve its stored settings,
  including the s…
summary: >-
  The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin
  through 1.0.3 does not perform any authorisation check on one of its REST API
  routes, allowing unauthenticated users to retrieve its stored settings,
  including the s…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-200
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77007'
references:
  - url: 'https://wpscan.com/vulnerability/24f1da87-4217-4876-a0f3-5e125f694651/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00256
epssPercentile: 0.17549
ingestedAt: '2026-08-30T07:49:07.719Z'
---

## Overview

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform any authorisation check on one of its REST API routes, allowing unauthenticated users to retrieve its stored settings, including the shared secret used to sign API requests to the connected BigBlueButton server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
