CVE-2026-16948
Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.
| Vendor | unknown |
| Product | solace extra |
| Published | Aug 8, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown solace extra
Be the first to know when new unknown vulnerabilities affecting unknown solace extra are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Solace Extra
0 < 1.6.1
References
Credits
JunHee CHO WPScan