# Video Conferencing with BigBlueButton (BBB) <= 3.2.16 - Unauthenticated Missing Authorization to Recording Exposure via Fluent Community Lesson Recordings Shortcode

- **ID:** WPSEC-2026-0755
- **Plugin:** Virtual Classroom & Video Conferencing – BigBlueButton (`video-conferencing-with-bbb`), https://wordpress.org/plugins/video-conferencing-with-bbb/
- **Affected versions:** from 3.2.16 before 3.2.17
- **Fixed in:** 3.2.17 (Update to 3.2.17 or later.)
- **Severity:** Low 3.7 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N)
- **Weakness:** CWE-862
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-10)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/video-conferencing-with-bbb
- **Fix released:** 2026-10-09
- **Published:** 2026-10-10
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0755/

## Description

The Virtual Classroom & Video Conferencing – BigBlueButton plugin for WordPress is vulnerable to unauthorized access of room recordings via the recordings shortcode rendered in Fluent Community course lessons in versions 3.2.16 up to, and including, 3.2.16. This is due to a missing authorization check in the course portal rendering path (portal_view_from_tokens_string). That path lists the recordings of every room named in the shortcode without the room-recording permission check that the regular recordings view applies. This makes it possible for unauthenticated attackers to view recording names and playback links for rooms that normally require an access code. The site must have Fluent Community configured with a public portal and public lesson viewing, and a lesson must contain a BigBlueButton recordings shortcode.

## References

- https://wpsec.com/vuln/WPSEC-2026-0755/
- https://plugins.svn.wordpress.org/video-conferencing-with-bbb/tags/3.2.17/
- https://wordpress.org/plugins/video-conferencing-with-bbb/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0755/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
