Executive brief
WP Learn Manager, a WordPress plugin used for managing educational content, contains a critical security flaw that allows unauthorized individuals to take control of a website. By exploiting this vulnerability, an attacker can remotely install and activate any plugin from the official WordPress repository without needing a password. This could lead to a full site takeover, data theft, or the installation of malicious software.
Technical details
The WP Learn Manager plugin for WordPress suffers from a missing authorization vulnerability (CWE-862) in its AJAX handling logic. Specifically, the plugin fails to perform adequate permission checks or nonce verification on functions responsible for plugin management. An unauthenticated remote attacker can exploit this by sending crafted requests to the site's AJAX endpoint, enabling them to install and activate any plugin available on WordPress.org. This can be leveraged to achieve full site compromise by installing plugins with known vulnerabilities or administrative utilities. The issue exists in all versions up to and including 1.1.8.
Affected products
- rabilal WP Learn Manager up to, and including, 1.1.8
Timeline
- 2026-07-08: advisory: NVD publication date
- 2026-07-08: disclosed: Wordfence advisory published
References
- https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/includes/ajax.php
- https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/includes/ajax.php
- https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/modules/jslearnmanager/model.php
- https://plugins.trac.wordpress.org/browser/learn-manager/tags/1.1.8/modules/jslearnmanager/model.php
- https://www.wordfence.com/threat-intel/vulnerabilities/id/8cbf5121-2511-4e21-a346-67fa1e34fc02?source=cve