THREAT OPS › Threat News › [NVD] CVE-2026-77010 (MEDIUM 6.5) — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class access code, allowing unauthenticated users to obtain a signed meeting join link for
[NVD] CVE-2026-77010 (MEDIUM 6.5) — The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class access code, allowing unauthenticated users to obtain a signed meeting join link for
CVE-2026-77010 CVSS: 6.5 MEDIUM Published: 2026-08-29T06:17:39.037
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation checks on its REST API routes and does not consistently enforce the per-class access code, allowing unauthenticated users to obtain a signed meeting join link for any classroom, including one protected by an access
Indicators of compromise
- CVE-2026-77010cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-77010