Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation
Summary
| CVE | CVE-2026-16256 |
|---|---|
| State | PUBLISHED |
| Assigner | WPScan |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-02 06:16:39 UTC |
| Updated | 2026-08-02 06:16:39 UTC |
| Description | The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site. |
Risk And Classification
Problem Types: CWE-269 Improper Privilege Management
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Unknown | POUCO Import Users | affected 1.0.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| wpscan.com/vulnerability/c7442f47-7263-4cbb-8157-a4ac69953c95 | [email protected] | wpscan.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Khaled Alenazi (Nxploited) (en)
CNA: WPScan (en)
There are currently no legacy QID mappings associated with this CVE.