CVE-2026-16965
Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
| Vendor | unknown |
| Product | solace extra |
| Published | Aug 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown solace extra
Be the first to know when new unknown vulnerabilities affecting unknown solace extra are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Solace Extra
0 < 1.6.1
References
Credits
JunHee CHO WPScan