Video Conferencing with BigBlueButton (BBB) <= 3.2.16 - Unauthenticated Missing Authorization to Recording Exposure via Fluent Community Lesson Recordings Shortcode

Low 3.7 CWE-862Fixed in 3.2.17
ID
WPSEC-2026-0755
Plugin
Virtual Classroom & Video Conferencing – BigBlueButton (video-conferencing-with-bbb)
Affected
from 3.2.16 before 3.2.17
Remediation
Update to 3.2.17 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness
CWE-862
Usage
Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-10
Attack surface
Video Conferencing with BigBlueButton (BBB) on WPSec AttackSurface
Fix released
Published

Description

The Virtual Classroom & Video Conferencing – BigBlueButton plugin for WordPress is vulnerable to unauthorized access of room recordings via the recordings shortcode rendered in Fluent Community course lessons in versions 3.2.16 up to, and including, 3.2.16. This is due to a missing authorization check in the course portal rendering path (portal_view_from_tokens_string). That path lists the recordings of every room named in the shortcode without the room-recording permission check that the regular recordings view applies. This makes it possible for unauthenticated attackers to view recording names and playback links for rooms that normally require an access code. The site must have Fluent Community configured with a public portal and public lesson viewing, and a lesson must contain a BigBlueButton recordings shortcode.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0