CVE-2026-2446 PUBLISHED

Powerpack for LearnDash < 1.3.0 - Unauthenticated Arbitrary Option Update

Assigner: WPScan
Reserved: 13.02.2026 Published: 06.03.2026 Updated: 06.03.2026

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

Product Status

Vendor Unknown
Product PowerPack for LearnDash
Versions Default: unaffected
  • affected from 0 to 1.3.0 (excl.)

Credits

  • Khaled Alenazi (Nxploited) finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE