CVE-2026-27535: WordPress Solace Extra plugin <= 1.6.0 - Broken Access Control vulnerability
Published Aug 13, 2026
·Updated
Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.
Affected Software
1 affected component
WordPress plugin/Solace Extra<=1.6.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/Solace Extrato a version that resolves this vulnerability.Fixed in 1.6.1
Event History
Aug 13, 2026
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27535?
The severity of CVE-2026-27535 is high with a CVSS score of 7.1.
2
What type of vulnerability is CVE-2026-27535?
CVE-2026-27535 is a Broken Access Control vulnerability found in the Solace Extra plugin for WordPress.
3
How does CVE-2026-27535 affect users?
CVE-2026-27535 allows subscribers to potentially gain unauthorized access to sensitive functionalities in the Solace Extra plugin.
4
How do I fix CVE-2026-27535?
To fix CVE-2026-27535, update the Solace Extra plugin to the latest version beyond 1.6.0.
5
When was CVE-2026-27535 published?
CVE-2026-27535 was published on August 13, 2026.