CVE-2026-18316: Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action

Published Aug 16, 2026
·
Updated

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the importzip() function in versions up to, and including, 1.6.0. The handler is registered on both wpajaxaction-import-zip and wpajaxnoprivaction-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wplocalizescript (unrestricted adminenqueuescripts hook) and is therefore accessible to any authenticated user including Subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to wipe navigation menus, sidebar widgets (via updateoption('sidebarswidgets', array())), all theme mods (via removethememods()), and Elementor templates, as well as trigger arbitrary demo-content imports.

Affected Software

1 affected component
Solace Extra<=1.6.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Solace Extra plugin for WordPress to a version that resolves this vulnerability.

    Fixed in 1.6.0
  2. Configuration

    Modify the Solace Extra plugin so the import_zip() handler performs an explicit WordPress capability/permission check before processing the AJAX request, and do not allow Subscriber-level (or unauthenticated) users via wp_ajax_nopriv_action-import-zip.

    WordPress Solace Extra plugin import_zip capability check on import_zip() (authorization) = Enforce a capability check so only authorized users can invoke import_zip() behind wp_ajax_action-import-zip/wp_ajax_nopriv_action-import-zip
  3. Compensating control

    If possible, restrict the ability to enqueue/emit the 'ajax-nonce' and limit access to the affected Solace Extra AJAX endpoints so that only users with sufficient privileges can reach wp_ajax_action-import-zip / wp_ajax_nopriv_action-import-zip (e.g., via plugin/endpoint-level access controls).

Event History

Aug 16, 2026
CVE Published
via MITRE·05:27 AM
Data Sourced
via MITRE·05:27 AM
DescriptionSeverityWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-18316?

CVE-2026-18316 has a critical severity score of 9.1.

2

What are the consequences of CVE-2026-18316?

CVE-2026-18316 allows unauthorized modification and potential loss of data due to missing capability checks.

3

Who is affected by CVE-2026-18316?

Users of the Solace Extra plugin for WordPress versions 1.6.0 and below are affected by CVE-2026-18316.

4

How do I fix CVE-2026-18316?

To fix CVE-2026-18316, update the Solace Extra plugin to the latest version that addresses this vulnerability.

5

What versions does CVE-2026-18316 impact?

CVE-2026-18316 impacts all versions of the Solace Extra plugin up to and including 1.6.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203