Junglewise Threat Intelligence

CVE-2026-77007: HEL Online Classroom unauthenticated API secret disclosure

CVE-2026-77007 · Severity: high · CVSS 7.5 · Published 2026-08-29

Executive brief

The HEL Online Classroom WordPress plugin, used to deliver AI-powered virtual classroom experiences, contains an authorization bypass in its REST API that allows unauthenticated users to retrieve sensitive configuration data. An attacker can obtain the shared secret credentials used to communicate with the BigBlueButton video conferencing service, potentially compromising meeting security and enabling unauthorized API calls to manipulate classroom sessions.

Technical details

The plugin fails to implement authorization checks on a REST API endpoint, allowing unauthenticated access to stored plugin settings. The root cause is the absence of capability or authentication validation before exposing sensitive configuration data via the REST API. An unauthenticated, network-based attacker can directly query the vulnerable endpoint to retrieve the BigBlueButton shared secret and other plugin configuration. This credential exposure enables an attacker to forge API requests to the BigBlueButton server, potentially creating, deleting, or manipulating classroom sessions. No fix has been reported at the time of publication.

Affected products

  • HEL Online Classroom HEL Online Classroom through 1.0.3

Timeline

  • 2026-08-27: disclosed
  • 2026-08-29: advisory

References