CVE-2026-2446

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users
Configurations

No configuration.

History

No history.

Information

Published : 2026-03-06 06:15

Updated : 2026-06-17 10:30


NVD link : CVE-2026-2446

Mitre link : CVE-2026-2446

CVE.ORG link : CVE-2026-2446


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization