PT-2026-39962 · Higheredlab+1 · Hel Online Classroom: Ai-Powered Online Classrooms+1
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
HEL Online Classroom: AI-powered Online Classrooms versions prior to 1.0.4
Description
Missing authorization in a REST API endpoint allows unauthenticated attackers to delete any classroom record. This occurs because the endpoint is registered with a
permission callback of return true, which bypasses all WordPress authentication and authorization checks. An attacker can trigger this by supplying the classroom ID in the request, leading to permanent data loss.Recommendations
Update the plugin to a version later than 1.0.3.
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hel Online Classroom: Ai-Powered Online Classrooms
Hel-Online-Classroom