What is CVE-2026-15312?
CVE-2026-15312 is a Privilege Escalation vulnerability found in the Propovoice plugin for WordPress (versions <=1.7.8). The issue exists because the `create()` function's REST endpoint fails to validate the user-supplied `role` parameter against an allowlist. Site administrators should immediately update to the latest patched version.
Azərbaycanca: CVE-2026-15312, WordPress üçün Propovoice plaginində (<=1.7.8) müəyyən edilmiş İmtiyaz Artırma (Privilege Escalation) zəifliyidir. Bu boşluq `create()` funksiyasının REST endpoint-də istifadəçi tərəfindən təqdim edilən `role` parametrini icazə verilən siyahı ilə yoxlamaması səbəbindən yaranır. Sayt administratorları plagini dərhal ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-269
FAQ1
How can the CVE-2026-15312 vulnerability in the Propovoice plugin be exploited?
The vulnerability arises because the `create()` function's REST endpoint does not validate the user-supplied `role` parameter against an allowlist. This allows an authenticated user to change their role and achieve Privilege Escalation.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.