CVE Database
/

CVE-2026-2446

Back to search

CVE-2026-2446

Published: Mar 6, 2026

Modified: Mar 6, 2026

PUBLISHED

Description

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

VendorProductVersions

Unknown

PowerPack for LearnDash

affected
0 - < 1.3.0

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now