CVE-2026-16256

CVE-2026-16256CVE-2026-16256

Description

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.

Scoring

Last modified2026-08-02
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.