๐Ÿ” CVE Alert

CVE-2026-16948

UNKNOWN 0.0

Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

Vendor unknown
Product solace extra
Published Aug 8, 2026
Stay Ahead of the Next One

Get instant alerts for unknown solace extra

Be the first to know when new unknown vulnerabilities affecting unknown solace extra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Solace Extra
0 < 1.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/50e47ee9-cffc-4435-bc77-77fc65e9ff16/

Credits

JunHee CHO WPScan