CVE-2026-16965: CWE-862 Missing Authorization in Solace Extra
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
AI Analysis
Technical Summary
CVE-2026-16965 describes a missing authorization vulnerability in the Solace Extra WordPress plugin prior to version 1.6.1. Specifically, the plugin does not perform capability or nonce checks in one of its AJAX actions, enabling authenticated users with minimal privileges or any logged-in user via CSRF to modify post meta data arbitrarily and deactivate active site templates. This can lead to unauthorized content manipulation and site configuration changes.
Potential Impact
The vulnerability allows unauthorized modification of post metadata and deactivation of active templates by low-privileged authenticated users or via CSRF by any logged-in user. This can degrade site integrity and availability by altering content and disabling active themes, but does not directly impact confidentiality or availability beyond these effects. The CVSS score is 4.3 (medium severity) reflecting limited impact and attack complexity.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, administrators should consider restricting access to authenticated users and implement additional protective measures such as CSRF protections or disabling the vulnerable AJAX action if possible.
CVE-2026-16965: CWE-862 Missing Authorization in Solace Extra
Description
The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.
CVSS v3.1
Score 4.3medium
Affected software
Solace Extra
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16965 describes a missing authorization vulnerability in the Solace Extra WordPress plugin prior to version 1.6.1. Specifically, the plugin does not perform capability or nonce checks in one of its AJAX actions, enabling authenticated users with minimal privileges or any logged-in user via CSRF to modify post meta data arbitrarily and deactivate active site templates. This can lead to unauthorized content manipulation and site configuration changes.
Potential Impact
The vulnerability allows unauthorized modification of post metadata and deactivation of active templates by low-privileged authenticated users or via CSRF by any logged-in user. This can degrade site integrity and availability by altering content and disabling active themes, but does not directly impact confidentiality or availability beyond these effects. The CVSS score is 4.3 (medium severity) reflecting limited impact and attack complexity.
Mitigation Recommendations
No official patch or remediation guidance is currently available. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is released, administrators should consider restricting access to authenticated users and implement additional protective measures such as CSRF protections or disabling the vulnerable AJAX action if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-24T08:20:08.897Z
- State
- PUBLISHED
Threat ID: 6a781a2ebf8831d5391ffede
Added to database: 08/09/2026, 06:11:58 UTC
Last enriched: 08/16/2026, 14:35:08 UTC
Last updated: 09/22/2026, 01:52:42 UTC
Views: 35
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.