CVE-2026-2446

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users
Configurations

No configuration.

History

06 Mar 2026, 18:16

Type Values Removed Values Added
CWE CWE-862
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8

06 Mar 2026, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-06 06:15

Updated : 2026-03-09 13:35


NVD link : CVE-2026-2446

Mitre link : CVE-2026-2446

CVE.ORG link : CVE-2026-2446


JSON object : View

Products Affected

No product.

CWE
CWE-862

Missing Authorization