
🚨*CVE* CVE-2026-16256 The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated users that create a… https://www.cve.org/CVERecord?id=CVE-2026-16256 ----- Traducción: CVE-2026-16256 El … http://infoflow.cloud`
Post summary
CVE-2026-16256 exposes unauthenticated privilege escalation in the POUCO Import Users WordPress plugin due to missing capability/nonce checks on AJAX actions. No PoC, exploit tool, or active exploitation reports are provided.


