CVE-2026-16948
8.1Solace · Solace Extra WordPress plugin
The Solace Extra WordPress plugin before 1.6.1 lacks capability checks in AJAX actions, allowing authenticated subscribers to modify site settings and delete content.
Executive summary
A critical access control vulnerability in the Solace Extra WordPress plugin allows low-privileged users to perform unauthorized administrative actions.
Vulnerability
This vulnerability involves missing capability checks in several AJAX actions and the insecure exposure of nonces on admin pages. The flaw allows an authenticated user with Subscriber-level privileges to bypass intended access controls and perform unauthorized operations.
Business impact
The ability for low-privileged users to modify site-wide presentation settings and delete imported site-builder content poses a significant risk to site integrity and availability. With a CVSS score of 8.1, this high-severity vulnerability could be leveraged to deface websites or disrupt operations, leading to potential reputational damage and data loss.
Remediation
Immediate Action: Update the Solace Extra plugin to version 1.6.1 or later immediately to implement proper capability checks.
Proactive Monitoring: Review WordPress access logs for unusual AJAX requests or unauthorized attempts to access administrative settings by Subscriber-level accounts.
Compensating Controls: Implement a Web Application Firewall to monitor and block suspicious AJAX traffic patterns while the update is being deployed.
Exploitation status
Public Exploit Available: No confirmed public weaponized exploit exists in the provided data.
Analyst recommendation
Given the severity of the unauthorized access enabled by this flaw, administrators should prioritize updating the Solace Extra plugin to version 1.6.1. Failure to apply this patch leaves the site vulnerable to administrative-level tampering by any registered user.