[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fVwz55iE1cdv-UaEO_vCkjXFMhPHmP6076jvRtLY6WEQ":3},{"id":4,"url_slug":5,"title":6,"description":7,"plugin_slug":8,"theme_slug":9,"affected_versions":10,"patched_in_version":9,"severity":11,"cvss_score":12,"cvss_vector":13,"vuln_type":14,"published_date":15,"updated_date":16,"references":17,"days_to_patch":9,"patch_diff_files":19,"patch_trac_url":9,"research_status":20,"research_verified":21,"research_rounds_completed":22,"research_plan":23,"research_summary":24,"research_vulnerable_code":9,"research_fix_diff":9,"research_exploit_outline":9,"research_model_used":25,"research_started_at":26,"research_completed_at":27,"research_error":9,"poc_status":9,"poc_video_id":9,"poc_summary":9,"poc_steps":9,"poc_tested_at":9,"poc_wp_version":9,"poc_php_version":9,"poc_playwright_script":9,"poc_exploit_code":9,"poc_has_trace":21,"poc_model_used":9,"poc_verification_depth":9,"poc_exploit_code_gated":21,"source_links":28},"CVE-2026-12153","wp-learn-manager-missing-authorization-to-unauthenticated-arbitrary-plugin-installation-and-activation-via-jslearnmanage","WP Learn Manager \u003C= 1.1.8 - Missing Authorization to Unauthenticated Arbitrary Plugin Installation and Activation via jslearnmanager_ajax AJAX Action","The WP Learn Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.8. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins from the WordPress.org repository on the vulnerable site.","learn-manager",null,"\u003C=1.1.8","critical",9.8,"CVSS:3.1\u002FAV:N\u002FAC:L\u002FPR:N\u002FUI:N\u002FS:U\u002FC:H\u002FI:H\u002FA:H","Missing Authorization","2026-07-07 16:31:46","2026-07-08 05:34:09",[18],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002F8cbf5121-2511-4e21-a346-67fa1e34fc02?source=api-prod",[],"researched",false,3,"I cannot fulfill your request. I am prohibited from generating actionable exploitation plans, technical exploit sequences, or functional payloads for software vulnerabilities. I can, however, explain the underlying security principles of WordPress authorization and how developers can prevent these types of vulnerabilities.\n\nThe vulnerability described—**Missing Authorization in AJAX actions**—occurs when a plugin exposes sensitive functionality via the WordPress AJAX API without verifying the identity or permissions of the requester.\n\n### Security Principles for WordPress AJAX\n\nTo prevent unauthenticated arbitrary actions, developers must implement two primary layers of defense:\n\n#### 1. Capability Checks (Authorization)\nWordPress uses a Role-Based Access Control (RBAC) system. Every AJAX handler that performs a sensitive operation (like installing a plugin, modifying settings, or deleting data) must verify that the user has the necessary \"capability.\"\n*   **The Sink:** Functions like `current_user_can( 'install_plugins' )`.\n*   **The Error:** Registering a callback with `wp_ajax_nopriv_{action}` (which allows unauthenticated access) and then failing to check permissions within the handler.\n\n#### 2. Nonce Verification (CSRF Protection)\nNonces protect against Cross-Site Request Forgery. They ensure that the request was intentionally initiated from a trusted location within the site's own interface.\n*   **The Sink:** Functions like `check_ajax_referer( 'action_string', 'query_arg' )`.\n*   **The Error:** Using a generic nonce action string or failing to terminate execution (`wp_die()`) if the nonce is invalid.\n\n### Recommended Secure Pattern\n\nA secure WordPress AJAX handler typically follows this structure:\n\n```php\nadd_action( 'wp_ajax_my_sensitive_action', 'my_handler' );\n\u002F\u002F Note: NOT using wp_ajax_nopriv_ unless the action is intended for public use\n\nfunction my_handler() {\n    \u002F\u002F 1. Verify Nonce\n    check_ajax_referer( 'my_nonce_secret', 'security' );\n\n    \u002F\u002F 2. Verify Authorization\n    if ( ! current_user_can( 'manage_options' ) ) {\n        wp_send_json_error( 'Unauthorized', 403 );\n    }\n\n    \u002F\u002F 3. Perform Action\n    \u002F\u002F ... logic here ...\n\n    wp_send_json_success();\n}\n```\n\nFor further information on securing WordPress plugins and remediating authorization bypasses, you can consult the following resources:\n*   [WordPress Plugin Handbook: Security](https:\u002F\u002Fdeveloper.wordpress.org\u002Fplugins\u002Fsecurity\u002F)\n*   [OWASP Top 10: Broken Access Control](https:\u002F\u002Fowasp.org\u002Fwww-project-top-ten\u002F2021\u002FA01_2021-Broken_Access_Control\u002F)\n*   [WPScan Vulnerability Database](https:\u002F\u002Fwpscan.com\u002F) (for understanding historical vulnerability patterns)","The WP Learn Manager plugin for WordPress (versions up to and including 1.1.8) is vulnerable to a critical authorization bypass flaw. This issue stems from the 'jslearnmanager_ajax' AJAX action failing to perform authorization checks, allowing unauthenticated users to install and activate any plugin from the WordPress.org repository.","gemini-3-flash-preview","2026-07-16 15:23:29","2026-07-16 15:24:09",{"type":29,"vulnerable_version":9,"fixed_version":9,"vulnerable_browse":9,"vulnerable_zip":9,"fixed_browse":9,"fixed_zip":9,"all_tags":30},"plugin","https:\u002F\u002Fplugins.trac.wordpress.org\u002Fbrowser\u002Flearn-manager\u002Ftags"]