CVE-2026-2446Disclosure

LOWCVSS 9.8 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress options (such as default_role etc) and create arbitrary admin users

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Exploit: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-03-06); latest day: 1
  • 5 total mentions across 4 days

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Mentions · 2026-03-11: 1Mentions · 2026-03-17: 1PoC Mentioned / Linked · 2026-03-17: 1Technical Details · 2026-03-06: 2Technical Details · 2026-03-07: 1Technical Details · 2026-03-11: 103-0603-0703-1103-17
Signal classification2 categories
Disclosure
480.0%
Exploit
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-062
Disclosure2
2026-03-071
Disclosure1
2026-03-111
Disclosure1
2026-03-171
Exploit1
Full discourse5 posts
  • Brinztech@Brinztech_com
    Exploit

    Brinztech Alert: Critical Exploit for CVE-2026-2446 (LearnDash Powerpack) on Sale https://www.brinztech.com/breach-alerts/brinztech-alert-critical-exploit-for-cve-2026-2446-learndash-powerpack-on-sale/

    Post summary

    The link advertises a sellable exploit for CVE-2026-2446, but no technical or patch details are provided, and no claims of active exploitation are made.

    0000042
    45 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2446 (CVSS:9.8, CRITICAL) is Awaiting Analysis. The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action,..https://nvd.nist.gov/vuln/detail/CVE-2026-2446 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The tweet announces a new critical vulnerability (CVE-2026-2446) affecting the PowerPack for LearnDash WordPress plugin, highlighting missing authorization and CSRF checks, but offers no PoC, exploit, or patch details.

    0000026
    172 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-2446 - Critical The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitrary WordPress option... https://www.thehackerwire.com/vulnerability/CVE-2026-2446/ https://t.co/YQ4m4fzJSt

    Post summary

    The tweet announces CVE-2026-2446 as a critical flaw in PowerPack for LearnDash, highlighting missing auth/CSRF checks that enable unauthenticated option modifications.

    0000056
    128 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-2446 The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitr… https://www.cve.org/CVERecord?id=CVE-2026-2446 ----- Traducción: CVE-2026-2446 El … http://infoflow.cloud`

    Post summary

    The post highlights CVE-2026-2446, describing a lack of authorization and CSRF checks in PowerPack for LearnDash that permits unauthenticated updates, but does not provide a PoC, exploit, or patch information.

    0000031
    56 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2446 The PowerPack for LearnDash WordPress plugin before 1.3.0 does not have authorization and CRSF checks in an AJAX action, allowing unauthenticated users to update arbitr… https://www.cve.org/CVERecord?id=CVE-2026-2446

    Post summary

    CVE-2026-2446 identifies a missing authorization and CSRF check in the PowerPack for LearnDash WordPress plugin, allowing unauthenticated users to update content via an AJAX action.

    00000146
    56.6K followersView on X

Explore more