The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered with a permission_callback of '__return_true', which bypasses all WordPress authentication and authorization checks. This makes it possible for unauthenticated attackers to delete any classroom record by supplying its ID in the request, resulting in permanent data loss.
Project Subscriptions
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 13 May 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Higheredlab
Higheredlab hel Online Classroom: Ai-powered Online Classrooms Wordpress Wordpress wordpress |
|
| Vendors & Products |
Higheredlab
Higheredlab hel Online Classroom: Ai-powered Online Classrooms Wordpress Wordpress wordpress |
Tue, 12 May 2026 08:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered with a permission_callback of '__return_true', which bypasses all WordPress authentication and authorization checks. This makes it possible for unauthenticated attackers to delete any classroom record by supplying its ID in the request, resulting in permanent data loss. | |
| Title | HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Missing Authorization to Unauthenticated Arbitrary Classroom Deletion via 'id' Parameter | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-05-12T16:47:34.987Z
Reserved: 2026-04-20T18:12:33.186Z
Link: CVE-2026-6708
No data.
Status : Deferred
Published: 2026-05-12T09:16:56.077
Modified: 2026-05-12T14:03:52.757
Link: CVE-2026-6708
No data.
OpenCVE Enrichment
Updated: 2026-05-13T10:51:24Z
Weaknesses