PT-2026-67100 · WordPress · Pouco Import Users
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
POUCO Import Users versions prior to 1.0.1
Description
The POUCO Import Users WordPress plugin fails to perform capability or nonce checks on AJAX actions available to unauthenticated users used for creating and updating WordPress accounts. Additionally, the plugin trusts a role value supplied by the user, which allows an unauthenticated attacker to create a new administrator account and gain full control of the site.
Recommendations
Update POUCO Import Users to a version newer than 1.0.0.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pouco Import Users