What is CVE-2026-16256?
CVE-2026-16256 is a critical flaw in the POUCO Import Users WordPress plugin (up to version 1.0.0) that allows unauthenticated attackers to create new administrator accounts via AJAX actions. Immediately deactivate the plugin or update to the latest version.
Azərbaycanca: CVE-2026-16256, POUCO Import Users WordPress plaginində (1.0.0 versiyasına qədər) tapılan kritik bir boşluqdur. Bu, autentifikasiya olunmamış hücumçulara AJAX əməliyyatları vasitəsilə yeni administrator hesabı yaratmağa imkan verir. Dərhal plagini deaktiv edin və ya ən son versiyaya yeniləyin.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
Does an attacker need to be authenticated to exploit CVE-2026-16256?
No, this vulnerability allows unauthenticated attackers to create administrator accounts.
What immediate action is recommended for users of the POUCO Import Users plugin upon discovery of this critical flaw?
The plugin should be immediately deactivated or updated to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.