CVE-2026-15312: Privilege Escalation in Propovoice: All-in-One Client Management System Plugin
The Propovoice: All-in-One Client Management System plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8. Authenticated attackers with `ndpv_manager`-level access can create a new WordPress user account with the `administrator` role assigned, achieving full vertical privilege escalation. Immediate action is required to update the plugin to a patched version.