CVE-2026-16948: Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16948?
The severity of CVE-2026-16948 is rated at 52, indicating a moderate risk level.
How do I fix CVE-2026-16948?
To fix CVE-2026-16948, update the Solace Extra WordPress plugin to version 1.6.1 or later.
What actions are affected by CVE-2026-16948?
CVE-2026-16948 affects several AJAX actions within the Solace Extra plugin that lack proper capability checks.
Who is impacted by CVE-2026-16948?
Users with low-privileged roles, such as Subscriber, are impacted by CVE-2026-16948, allowing them unauthorized modifications.
What is the nature of the vulnerability in CVE-2026-16948?
CVE-2026-16948 is characterized by missing authorization due to the exposure of site-wide nonces on admin pages.