WordPress Plugin Vulnerabilities

Pouco Import Users <= 1.0.0 - Unauthenticated Privilege Escalation

Description

The plugin does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create and update WordPress accounts, and it trusts an attacker-supplied role value, allowing unauthenticated attackers to create a new administrator account and take over the site.

Proof of Concept

Affects Plugins

References

Classification

Miscellaneous

Original Researcher
Khaled Alenazi (Nxploited)
Submitter
Khaled Alenazi (Nxploited)
Submitter website
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-07-20 (about 13 days ago)
Added
2026-07-20 (about 12 days ago)
Last Updated
2026-07-20 (about 12 days ago)

Other