Brinztech@Brinztech_comExploit
The link advertises a sellable exploit for CVE-2026-2446, but no technical or patch details are provided, and no claims of active exploitation are made.
CRAC Learning - Tech@cracbotDisclosure
The tweet announces a new critical vulnerability (CVE-2026-2446) affecting the PowerPack for LearnDash WordPress plugin, highlighting missing authorization and CSRF checks, but offers no PoC, exploit, or patch details.
The Hacker Wire@TheHackerWireDisclosure
The tweet announces CVE-2026-2446 as a critical flaw in PowerPack for LearnDash, highlighting missing auth/CSRF checks that enable unauthenticated option modifications.
Infoflowcloud@infoflowcloudDisclosure
The post highlights CVE-2026-2446, describing a lack of authorization and CSRF checks in PowerPack for LearnDash that permits unauthenticated updates, but does not provide a PoC, exploit, or patch information.
CVE@CVEnewDisclosure
CVE-2026-2446 identifies a missing authorization and CSRF check in the PowerPack for LearnDash WordPress plugin, allowing unauthenticated users to update content via an AJAX action.