CVE-2026-16256: Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16256?
CVE-2026-16256 has a risk rating of 95, indicating a critical vulnerability.
How do I fix CVE-2026-16256?
To address CVE-2026-16256, update the POUCO Import Users WordPress plugin to version 1.0.1 or later.
What type of vulnerability is CVE-2026-16256?
CVE-2026-16256 is an unauthenticated privilege escalation vulnerability.
Who is affected by CVE-2026-16256?
Any WordPress site using the POUCO Import Users plugin version 1.0.0 or earlier is vulnerable to CVE-2026-16256.
What can an attacker do with CVE-2026-16256?
An attacker can exploit CVE-2026-16256 to create and update WordPress accounts, potentially granting themselves administrative access.