Junglewise Threat Intelligence

CVE-2026-16256: POUCO Import Users privilege escalation via unauthenticated AJAX

CVE-2026-16256 · Severity: critical · CVSS 9.8 · Published 2026-08-02

Executive brief

The POUCO Import Users WordPress plugin is vulnerable to an unauthenticated privilege escalation attack. An attacker can bypass security checks to create a new administrator account on any WordPress site running the vulnerable plugin, allowing complete takeover of the site and access to all customer data and settings.

Technical details

The plugin fails to implement capability and nonce verification on its AJAX actions for account creation and modification. Unauthenticated users can call these AJAX endpoints with attacker-supplied role values, enabling the creation of arbitrary administrator accounts. The vulnerability requires network access to a WordPress installation with the plugin active, but no authentication or user interaction is required. An attacker can fully compromise the WordPress site, including access to all databases, uploaded files, and administrative functionality.

Affected products

  • POUCO Import Users through 1.0.0

Timeline

  • 2026-07-20: disclosed
  • 2026-08-02: advisory

References