---
id: CVE-2026-77008
title: >-
  The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin
  through 1.0.3 does not have any authorisation or authentication check when
  saving its settings, allowing unauthenticated users to overwrite them and
  repoint every on…
summary: >-
  The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin
  through 1.0.3 does not have any authorisation or authentication check when
  saving its settings, allowing unauthenticated users to overwrite them and
  repoint every on…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'
cwe:
  - CWE-284
published: '2026-08-29'
updated: '2026-08-30'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-77008'
references:
  - url: 'https://wpscan.com/vulnerability/529663a1-87ed-4cff-92f5-85641e9718b3/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00246
epssPercentile: 0.16195
ingestedAt: '2026-08-30T07:49:07.761Z'
---

## Overview

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or authentication check when saving its settings, allowing unauthenticated users to overwrite them and repoint every online classroom, along with the shared secret those sessions are signed with, at infrastructure of their choosing.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
