CVE-2026-16948
Received Received - Intake

Solace WordPress Plugin Authenticated Settings Modification

Vulnerability report for CVE-2026-16948, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-08

Last updated on: 2026-08-08

Assigner: WPScan

Description

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-08
Last Modified
2026-08-08
Generated
2026-08-08
AI Q&A
2026-08-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
solace_extra wordpress_plugin to 1.6.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Solace Extra WordPress plugin before version 1.6.1 has missing authorization checks in its AJAX actions. This allows users with Subscriber-level access or higher to exploit exposed nonces on admin pages. They can modify site-wide presentation settings and delete imported site-builder content.

Detection Guidance

Check the installed version of the Solace Extra WordPress plugin. If it is below 1.6.1, the system is vulnerable. Look for unauthorized changes to site-wide presentation settings or missing imported site-builder content.

Impact Analysis

An attacker with Subscriber access could change your website's appearance, delete important site-builder content, or disrupt site functionality. This could lead to defacement, loss of customizations, or broken layouts.

Compliance Impact

This vulnerability allows low-privileged users to modify site-wide settings and delete content, which could lead to unauthorized changes in data handling or presentation. Such unauthorized access may violate compliance requirements under GDPR or HIPAA if it involves protected data or alters records.

Mitigation Strategies

Update the Solace Extra WordPress plugin to version 1.6.1 or later immediately. Review admin pages for unauthorized changes and remove any suspicious user accounts with Subscriber-level access or higher.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16948. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart