Video Conferencing with BigBlueButton (BBB) <= 3.2.16 - Unauthenticated Missing Authorization to Recording Exposure via Fluent Community Lesson Recordings Shortcode
- ID
- WPSEC-2026-0755
- Plugin
- Virtual Classroom & Video Conferencing – BigBlueButton (video-conferencing-with-bbb)
- Affected
- from 3.2.16 before 3.2.17
- Remediation
- Update to 3.2.17 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
- Weakness
- CWE-862
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
- Attack surface
- Video Conferencing with BigBlueButton (BBB) on WPSec AttackSurface
- Fix released
- Published
Description
The Virtual Classroom & Video Conferencing – BigBlueButton plugin for WordPress is vulnerable to unauthorized access of room recordings via the recordings shortcode rendered in Fluent Community course lessons in versions 3.2.16 up to, and including, 3.2.16. This is due to a missing authorization check in the course portal rendering path (portal_view_from_tokens_string). That path lists the recordings of every room named in the shortcode without the room-recording permission check that the regular recordings view applies. This makes it possible for unauthenticated attackers to view recording names and playback links for rooms that normally require an access code. The site must have Fluent Community configured with a public portal and public lesson viewing, and a lesson must contain a BigBlueButton recordings shortcode.
References
- https://wpsec.com/vuln/WPSEC-2026-0755/
- https://plugins.svn.wordpress.org/video-conferencing-with-bbb/tags/3.2.17/
- https://wordpress.org/plugins/video-conferencing-with-bbb/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS