Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical1
High0
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-08-05

CVE-2026-16256 - Pouco Import Users Plugin

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.

PLUGIN Pouco Import Users

CVE-2026-16256

CRITICAL CVSS 9.8 2026-08-02
Scroll to top