CVE-2026-16256
critical · 9.8The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.
9.8
CVSS
0.3%
EPSS (exploit prob.)
23rd
EPSS percentile
2026-08-02
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-269
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-16256