Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical1
High0
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-04-15

CVE-2026-2446 - Powerpack For Learndash Plugin

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

PLUGIN Powerpack For Learndash

CVE-2026-2446

CRITICAL CVSS 9.8 2026-03-06
Scroll to top