CVE-2025-68911: WordPress Solace theme <= 2.1.16 - Broken Access Control vulnerability
Missing Authorization vulnerability in solacewp Solace solace allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Solace: from n/a through <= 2.1.16.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68911?
CVE-2025-68911 has a high severity level due to its potential for unauthorized access and exploitation.
How do I fix CVE-2025-68911?
To fix CVE-2025-68911, update the Solace theme to version 2.1.17 or later, which addresses the broken access control issue.
Who is affected by CVE-2025-68911?
Users of the Solace theme version 2.1.16 and earlier on WordPress are affected by CVE-2025-68911.
What impact does CVE-2025-68911 have?
CVE-2025-68911 can allow attackers to bypass authorization and gain access to restricted functionalities within the WordPress site.
Is there a workaround for CVE-2025-68911?
While the best solution is to update the theme, temporarily disabling certain functionalities may serve as a workaround until a patch is applied.