{"api_version":"1","generated_at":"2026-08-02T20:38:51+00:00","cve":"CVE-2026-16256","urls":{"html":"https://cve.report/CVE-2026-16256","api":"https://cve.report/api/cve/CVE-2026-16256.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2026-16256","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2026-16256"},"summary":{"title":"Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation","description":"The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.","state":"PUBLISHED","assigner":"WPScan","published_at":"2026-08-02 06:16:39","updated_at":"2026-08-02 06:16:39"},"problem_types":["CWE-269 Improper Privilege Management"],"metrics":[],"references":[{"url":"https://wpscan.com/vulnerability/c7442f47-7263-4cbb-8157-a4ac69953c95/","name":"https://wpscan.com/vulnerability/c7442f47-7263-4cbb-8157-a4ac69953c95/","refsource":"contact@wpscan.com","tags":[],"title":"","mime":"","httpstatus":"","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-16256","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-16256","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"Unknown","product":"POUCO Import Users","version":"affected 1.0.0 semver","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[{"source":"CNA","value":"Khaled Alenazi (Nxploited)","lang":"en"},{"source":"CNA","value":"WPScan","lang":"en"}],"nvd_cpes":[],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"cna":{"affected":[{"defaultStatus":"unknown","product":"POUCO Import Users","vendor":"Unknown","versions":[{"lessThanOrEqual":"1.0.0","status":"affected","version":"0","versionType":"semver"}]}],"credits":[{"lang":"en","type":"finder","value":"Khaled Alenazi (Nxploited)"},{"lang":"en","type":"coordinator","value":"WPScan"}],"descriptions":[{"lang":"en","value":"The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site."}],"problemTypes":[{"descriptions":[{"description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}]}],"providerMetadata":{"dateUpdated":"2026-08-02T06:00:10.406Z","orgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","shortName":"WPScan"},"references":[{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/c7442f47-7263-4cbb-8157-a4ac69953c95/"}],"source":{"discovery":"EXTERNAL"},"title":"Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation","x_generator":{"engine":"WPScan CVE Generator"}}},"cveMetadata":{"assignerOrgId":"1bfdd5d7-9bf6-4a53-96ea-42e2716d7a81","assignerShortName":"WPScan","cveId":"CVE-2026-16256","datePublished":"2026-08-02T06:00:10.406Z","dateReserved":"2026-07-20T08:25:18.184Z","dateUpdated":"2026-08-02T06:00:10.406Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.2"},"nvd":{"publishedDate":"2026-08-02 06:16:39","lastModifiedDate":"2026-08-02 06:16:39","problem_types":["CWE-269 Improper Privilege Management"],"metrics":[],"configurations":[]},"legacy_mitre":{"record":{"CveYear":"2026","CveId":"16256","Ordinal":"1","Title":"Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalati","CVE":"CVE-2026-16256","Year":"2026"},"notes":[{"CveYear":"2026","CveId":"16256","Ordinal":"1","NoteData":"The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.","Type":"Description","Title":"Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalati"}]}}}