Description
The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site.
Published: 2026-07-08
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WP Learn Manager plugin for WordPress is vulnerable to an authorization bypass that allows unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository. This flaw stems from the plugin failing to verify that the user is authorized to perform the installation action, a weakness that maps to CWE-862. When exploited, the attacker can effectively run arbitrary code on the server by enabling a malicious plugin, potentially compromising the entire site and its data.

Affected Systems

All instances of the WP Learn Manager plugin developed by rabilal, with affected versions up to and including 1.1.8. Users with sites running any of these plugin versions before the mitigated release are at risk.

Risk and Exploitability

The vulnerability carries a CVSS score of 9.8, indicating critical severity. The EPSS score is < 1%, indicating a low probability of exploitation, but the lack of listed exploitation in the KEV catalog does not diminish the immediate risk because the flaw permits direct remote code execution via the publicly reachable AJAX endpoint. The likely attack vector involves an unauthenticated HTTP request to the jslearnmanager_ajax Ajax action, which the plugin accepts without sufficient authorization checks. Given the low barrier to exploitation, administrators should treat this as a high priority threat.

Generated by OpenCVE AI on July 29, 2026 at 14:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the WP Learn Manager plugin to a version that addresses the authorization bypass, preferably the latest available release.
  • If an immediate update is not possible, disable or remove the jslearnmanager_ajax endpoint by deactivating the plugin or applying a temporary action until a fix is applied.
  • Once the plugin is updated, perform a comprehensive review of active plugins and remove any that were installed without proper review or approval to mitigate any potential compromise.

Generated by OpenCVE AI on July 29, 2026 at 14:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Rabilal
Rabilal wp Learn Manager
Wordpress
Wordpress wordpress
Vendors & Products Rabilal
Rabilal wp Learn Manager
Wordpress
Wordpress wordpress

Wed, 08 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Description The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site.
Title WP Learn Manager <= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Rabilal Wp Learn Manager
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-07-08T17:10:10.951Z

Reserved: 2026-06-12T18:22:34.569Z

Link: CVE-2026-12153

cve-icon Vulnrichment

Updated: 2026-07-08T13:47:36.333Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses