GHSA-mxgq-qrj9-vj5p · Severity: medium — The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to...
The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.0.3. This is due to a missing capability check on a REST API endpoint registered with a permission_callback of '__return_true', which bypasses all WordPress authentication and authorization checks. This makes it possible for unauthenticated attackers to delete any classroom record by supplying its ID in the request, resulting in permanent data loss.
Conclusion & alert: CVE-2026-6708 is rated Moderate Risk (40.1/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.30%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-13 | 0.16% | 0.30% | +0.14% |
| 2 | 2026-05-18 | 0.13% | 0.16% | +0.03% |
| 3 | 2026-05-12 | — | 0.13% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
GHSA-mxgq-qrj9-vj5p · Severity: medium — The HEL Online Classroom: AI-powered Online Classrooms plugin for WordPress is vulnerable to...
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| No affected products in dataset. | |||