The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered with a permission_callback of '__return_true', which bypasses all WordPress authentication and authorization checks. This makes it possible for unauthenticated attackers to delete any classroom record by supplying its ID in the request, resulting in permanent data loss.
Metrics
Affected Vendors & Products
References
History
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Higheredlab
Higheredlab hel Online Classroom: Ai-powered Online Classrooms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Higheredlab
Higheredlab hel Online Classroom: Ai-powered Online Classrooms Wordpress Wordpress wordpress |
Tue, 12 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered with a permission_callback of '__return_true', which bypasses all WordPress authentication and authorization checks. This makes it possible for unauthenticated attackers to delete any classroom record by supplying its ID in the request, resulting in permanent data loss. | |
| Title | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Classroom Deletion via 'id' Parameter | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published: 2026-05-12T07:48:15.695Z
Updated: 2026-05-12T16:47:34.987Z
Reserved: 2026-04-20T18:12:33.186Z
Link: CVE-2026-6708
No data.
Status : Deferred
Published: 2026-05-12T09:16:56.077
Modified: 2026-05-12T14:03:52.757
Link: CVE-2026-6708
No data.