CVE detail
CVE-2026-15312
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. This is due to the `create()` function's REST endpoint failing to validate the user-supplied `role` parameter against an allowlist of permitted WordPress roles and omitting any `promote_users` capability check before passing the sanitized value directly to `WP_User::set_role()`. This makes it possible for authenticated attackers with `ndpv_manager`-level access and above to create a new WordPress user account with the `administrator` role assigned, achieving full vertical privilege escalation. The `ndpv_manager` capability is a sub-administrator CRM team role granted by Propovoice itself, meaning the attack surface extends beyond site administrators to any user the plugin has elevated to a manager position.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 17.9 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 5
- within the 30d window
- Peak daily
- 5
- highest bucket
Evidence
Source links by recency
5 source links · newest first
- https://www.wordfence.com/threat-intel/vulnerabilities/id/6a39e4d4-890d-46f9-8bb9-0fc858e6f1e2?source=cvewww.wordfence.com
No excerpt available.
Patchwww.wordfence.comAug 15, 2026, 3:16 AM - https://plugins.trac.wordpress.org/browser/propovoice/trunk/includes/Api/Type/Team.php#L423plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 15, 2026, 3:16 AM - https://plugins.trac.wordpress.org/browser/propovoice/trunk/includes/Api/Type/Team.php#L38plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 15, 2026, 3:16 AM - https://plugins.trac.wordpress.org/browser/propovoice/trunk/includes/Api/Type/Team.php#L219plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 15, 2026, 3:16 AM - https://plugins.trac.wordpress.org/browser/propovoice/trunk/includes/Api/Type/Team.php#L169plugins.trac.wordpress.org
No excerpt available.
Patchplugins.trac.wordpress.orgAug 15, 2026, 3:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73974CVSS 5.5 · Medium
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper acro…
- CVE-2026-73973CVSS 5.5 · Medium
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --fi…
- CVE-2026-75924CVSS 8.7 · High
A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secret across all namespaces. Addi…
- CVE-2026-75857CVSS 7.3 · High
CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement returns ApprovalRequirement::Au…
- CVE-2026-74965CVSS 8.8 · High
Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thunderbird 140.14, a…
- CVE-2026-74955CVSS 8.8 · High
Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.