Junglewise Threat Intelligence

CVE-2026-15312: Propovoice All-in-One Client Management System privilege escalation in user creation

CVE-2026-15312 · Severity: high · CVSS 8.8 · Published 2026-08-15

Executive brief

Propovoice is a WordPress plugin that provides client management and team collaboration features. A vulnerability in its user creation function allows team managers and higher-level users to create new WordPress administrator accounts without proper authorization checks, giving them complete control over the website.

Technical details

The vulnerability exists in the `create()` function's REST endpoint, which accepts a user-supplied `role` parameter without validating it against a whitelist of permitted WordPress roles. The endpoint also fails to check for the `promote_users` capability before calling `WP_User::set_role()`. An authenticated attacker with the `ndpv_manager` capability (a sub-administrator role assigned by the plugin) can exploit this to create a new user account with the `administrator` role, achieving full privilege escalation. The attack requires only authentication with plugin-granted manager-level access, making it exploitable by a broader set of users than standard WordPress administrators.

Affected products

  • Propovoice Propovoice: All-in-One Client Management System up to and including 1.7.8

Timeline

  • 2026-08-15: disclosed
  • 2026-08-15: advisory: CVE-2026-15312

References