CVE-2026-18316: CWE-862 Missing Authorization in solacewp Solace Extra
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script (unrestricted admin_enqueue_scripts hook) and is therefore accessible to any authenticated user including Subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to wipe navigation menus, sidebar widgets (via update_option('sidebars_widgets', array())), all theme mods (via remove_theme_mods()), and Elementor templates, as well as trigger arbitrary demo-content imports.
AI Analysis
Technical Summary
CVE-2026-18316 is a missing authorization vulnerability (CWE-862) in the Solace Extra WordPress plugin (up to version 1.6.0). The import_zip() function is exposed via AJAX endpoints (wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip) and only validates an 'ajax-nonce' that is accessible to all authenticated users, including low-privilege roles such as Subscribers. Due to the absence of proper capability checks, attackers with minimal privileges can exploit this to modify or delete critical site data including navigation menus, sidebar widgets, theme modifications, Elementor templates, and can trigger arbitrary demo-content imports.
Potential Impact
An attacker with authenticated access at Subscriber level or higher can exploit this vulnerability to cause significant integrity damage by wiping navigation menus, sidebar widgets, theme modifications, Elementor templates, and importing arbitrary demo content. This results in loss of site configuration and potentially disrupts site functionality and appearance. The CVSS score of 9.1 (critical) reflects the high impact on integrity and availability with no user interaction required and network attack vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict plugin usage to trusted users only and consider disabling or removing the Solace Extra plugin if possible. Monitor for vendor updates or security advisories addressing this issue.
CVE-2026-18316: CWE-862 Missing Authorization in solacewp Solace Extra
Description
The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script (unrestricted admin_enqueue_scripts hook) and is therefore accessible to any authenticated user including Subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to wipe navigation menus, sidebar widgets (via update_option('sidebars_widgets', array())), all theme mods (via remove_theme_mods()), and Elementor templates, as well as trigger arbitrary demo-content imports.
CVSS v3.1
Score 9.1critical
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-18316 is a missing authorization vulnerability (CWE-862) in the Solace Extra WordPress plugin (up to version 1.6.0). The import_zip() function is exposed via AJAX endpoints (wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip) and only validates an 'ajax-nonce' that is accessible to all authenticated users, including low-privilege roles such as Subscribers. Due to the absence of proper capability checks, attackers with minimal privileges can exploit this to modify or delete critical site data including navigation menus, sidebar widgets, theme modifications, Elementor templates, and can trigger arbitrary demo-content imports.
Potential Impact
An attacker with authenticated access at Subscriber level or higher can exploit this vulnerability to cause significant integrity damage by wiping navigation menus, sidebar widgets, theme modifications, Elementor templates, and importing arbitrary demo content. This results in loss of site configuration and potentially disrupts site functionality and appearance. The CVSS score of 9.1 (critical) reflects the high impact on integrity and availability with no user interaction required and network attack vector.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict plugin usage to trusted users only and consider disabling or removing the Solace Extra plugin if possible. Monitor for vendor updates or security advisories addressing this issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Wordfence
- Date Reserved
- 2026-07-29T18:20:00.202Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a814d98bf8831d5398c6b32
Added to database: 08/16/2026, 05:41:44 UTC
Last enriched: 08/23/2026, 13:28:23 UTC
Last updated: 09/09/2026, 22:52:09 UTC
Views: 105
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.