CVE-2026-2446

CRITICAL

PowerPack for LearnDash <1.3.0 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

References (1)

Core 1
Core References
Third Party Advisory exploit vdb-entry technical-description
https://wpscan.com/vulnerability/cbc95cea-e5d4-4874-add6-c8c728b683b7/

Scores

CVSS v3 9.8
EPSS 0.0030
EPSS Percentile 21.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-862
Status published
Published Mar 06, 2026
Tracked Since Mar 06, 2026