Impact
The HEL Online Classroom: AI-powered Online Classroom WordPress plugin, up to version 1.0.3, fails to verify that a user is authenticated or authorized before persisting configuration changes. An unauthenticated attacker can submit a request to the plugin’s settings endpoint, overwriting the classroom mapping and the shared secret used to sign session tokens. This allows the attacker to redirect any online classroom session to an infrastructure of their choice, potentially exposing sensitive data or facilitating impersonation of instructors and students.
Affected Systems
The vulnerability affects the HEL Online Classroom: AI-powered Online Classroom WordPress plugin, versions 1.0.3 or earlier, on any WordPress installation that has the plugin active. No specific vendor is listed, but the product name above is the target.
Risk and Exploitability
The vulnerability can be exploited by any entity that can reach the WordPress site, as authenticated or authorized checks are missing. Because the exploit requires only a simple HTTP request to the plugin’s settings endpoint and no authentication, the risk of exploitation remains high, with a CVSS score of 6.5 and an EPSS score of < 1%. The plugin’s status in the CISA KEV catalog is false, indicating it is not a known exploited vulnerability yet. Attackers can perform the exploitation by sending a simple HTTP request to the plugin’s settings URL, making this a straightforward and likely‑to‑be-successful attack if the vulnerability remains unpatched.
OpenCVE Enrichment