Impact
The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin fails to enforce an authorization check on one of its REST API routes. An unauthenticated requester can retrieve the plugin's stored configuration, which includes the shared secret used to sign requests to the connected BigBlueButton server. With this secret in hand, the attacker could forge API calls to BigBlueButton, potentially creating, modifying, or joining meetings, thereby compromising the integrity and availability of the virtual classroom environment.
Affected Systems
The vulnerability is present in the HEL Online Classroom: AI-powered Online Classrooms WordPress plugin version 1.0.3 and all earlier releases. Any WordPress site that has installed this plugin with a version no newer than 1.0.3 is at risk. The issue appears to be uncovered for the entire range of affected releases, with no indication of a vendor‑supplied fix at the time of the advisory.
Risk and Exploitability
Attackers can exploit the unauthenticated endpoint by sending a simple HTTP request to the exposed REST route, which returns the complete set of plugin settings including the sensitive BigBlueButton API secret. Because the secret is essential for authenticating API requests, its disclosure allows the attacker to perform privileged operations on the BigBlueButton server without any prior authentication to the WordPress site. The vulnerability is therefore high‑risk for any site using the vulnerable plugin, but the EPSS score is not available and the issue is not listed in the CISA KEV catalog. Prompt remediation is advised to prevent potential abuse.
OpenCVE Enrichment