Vulnerability Bulletins |
CVE-2026-2446 |
|
| Affected software | WORDPRESS |
| The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users | |
Link: |
|
| https://nvd.nist.gov/vuln/detail/CVE-2026-2446 | |






