Impact
The HEL Online Classroom: AI‑powered Online Classrooms WordPress plugin up to version 1.0.3 fails to enforce authorization on its REST API endpoints and consistently checks the per‑class access code. This flaw allows any visitor to request a signed meeting join link and then join the class with moderator privileges, effectively granting an unauthenticated attacker full control over the session.
Affected Systems
The vulnerability affects installations of the HEL Online Classroom: AI‑powered Online Classrooms plugin for WordPress running version 1.0.3 or earlier. No other products or versions were identified as impacted by the corresponding CNA.
Risk and Exploitability
The lack of authorization checks makes the flaw highly exploitable from any location over the internet via simple REST API calls. The EPSS score is < 1% and the CVSS score of 6.5 indicates a moderate‑severe risk. The vulnerability is not listed in CISA’s KEV catalog, but the potential to compromise entire class sessions warrants urgent remediation.
OpenCVE Enrichment