CVE-2026-16965 PUBLISHED

Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status

Assigner: WPScan
Reserved: 24.07.2026 Published: 09.08.2026 Updated: 09.08.2026

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.

Product Status

Vendor Unknown
Product Solace Extra
Versions Default: unaffected
  • affected from 0 to 1.6.1 (excl.)

Credits

  • JunHee CHO finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE
  • CWE-352 Cross-Site Request Forgery (CSRF) CWE