Executive brief
Propovoice is a WordPress plugin that provides client management and team collaboration features. A vulnerability in its user creation function allows team managers and higher-level users to create new WordPress administrator accounts without proper authorization checks, giving them complete control over the website.
Technical details
The vulnerability exists in the `create()` function's REST endpoint, which accepts a user-supplied `role` parameter without validating it against a whitelist of permitted WordPress roles. The endpoint also fails to check for the `promote_users` capability before calling `WP_User::set_role()`. An authenticated attacker with the `ndpv_manager` capability (a sub-administrator role assigned by the plugin) can exploit this to create a new user account with the `administrator` role, achieving full privilege escalation. The attack requires only authentication with plugin-granted manager-level access, making it exploitable by a broader set of users than standard WordPress administrators.
Affected products
- Propovoice Propovoice: All-in-One Client Management System up to and including 1.7.8
Timeline
- 2026-08-15: disclosed
- 2026-08-15: advisory: CVE-2026-15312