New Vulnerability (CVE-2026-77010) Disclosed in HEL Online Classroom WordPress Plugin
NIST has published details for CVE-2026-77010, a vulnerability in the HEL Online Classroom: AI-powered Online Classrooms WordPress plugin (through version 1.0.3). The flaw allows unauthenticated users to obtain signed meeting join links with moderator privileges due to insufficient authorization checks on REST API routes and inconsistent enforcement of access codes.
Want more?
Open NewsSnap.ai for the full app experience, including audio, personalization, and more news tools.