PT-2026-69182 · WordPress · Solace Extra
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Solace Extra versions prior to 1.6.1
Description
Insufficient capability checks in several AJAX actions, combined with the exposure of the protecting nonce on admin pages accessible to low-privileged users, allow individuals with roles as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content. A nonce is a unique token used to protect against cross-site request forgery.
Recommendations
Update Solace Extra to version 1.6.1 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solace Extra