The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
History

Tue, 11 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 09 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-352

Sun, 09 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
Title Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-09T06:00:11.831Z

Updated: 2026-08-11T19:43:41.456Z

Reserved: 2026-07-24T08:20:08.897Z

Link: CVE-2026-16965

cve-icon Vulnrichment

Updated: 2026-08-11T19:43:34.773Z

cve-icon NVD

Status : Received

Published: 2026-08-09T06:17:55.770

Modified: 2026-08-11T20:17:33.707

Link: CVE-2026-16965

cve-icon Redhat

No data.