---
id: CVE-2026-16256
title: >-
  The POUCO Import Users WordPress plugin through 1.0.0 does not perform any
  capability or nonce checks on AJAX actions available to unauthenticated users
  that create and update WordPress accounts, and it trusts an attacker-supplied
  role v…
summary: >-
  The POUCO Import Users WordPress plugin through 1.0.0 does not perform any
  capability or nonce checks on AJAX actions available to unauthenticated users
  that create and update WordPress accounts, and it trusts an attacker-supplied
  role v…
severity: none
published: '2026-08-02'
updated: '2026-08-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-16256'
references:
  - url: 'https://wpscan.com/vulnerability/c7442f47-7263-4cbb-8157-a4ac69953c95/'
    label: contact@wpscan.com
tags:
  - nvd
ingestedAt: '2026-08-02T13:18:29.319Z'
epss: 0.00303
epssPercentile: 0.23232
---

## Overview

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
