PT-2026-39962 · Higheredlab+1 · Hel Online Classroom: Ai-Powered Online Classrooms+1

·

CVE-2026-6708

·

Published

2026-05-11

·

Updated

2026-05-12

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions HEL Online Classroom: AI-powered Online Classrooms versions prior to 1.0.4
Description Missing authorization in a REST API endpoint allows unauthenticated attackers to delete any classroom record. This occurs because the endpoint is registered with a permission callback of return true, which bypasses all WordPress authentication and authorization checks. An attacker can trigger this by supplying the classroom ID in the request, leading to permanent data loss.
Recommendations Update the plugin to a version later than 1.0.3.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6708

Affected Products

Hel Online Classroom: Ai-Powered Online Classrooms
Hel-Online-Classroom