CVE Explorer
CVE-2026-16256
The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unknown","product":"POUCO Import Users","vendor":"Unknown","versions":[{"lessThanOrEqual":"1.0.0","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:a28e9f75074a95e3449ee579d6b8ae734422711e19a8068069a6c34a13952185 · sha256:1efe4404a9a32793… · /containers/cna/affected/0
CWE assertions
1 source assertion{"description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:a28e9f75074a95e3449ee579d6b8ae734422711e19a8068069a6c34a13952185 · sha256:1efe4404a9a32793… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/c7442f47-7263-4cbb-8157-a4ac69953c95/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:a28e9f75074a95e3449ee579d6b8ae734422711e19a8068069a6c34a13952185 · sha256:1efe4404a9a32793… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.