The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.
CVE-2026-16948
NONE
EPSS 0.13%
Updated Aug 08, 2026
Unknown
unknown:solace extra
CVE Details
CVE ID
CVE-2026-16948
Published Date
Aug 08, 2026
Vendor
Unknown
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.13%
Likelihood of exploitation in next 30 days
Percentile:
3.2th percentile (higher than 3.2% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory