PT-2026-69264 · WordPress · Solace Extra
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Solace Extra versions prior to 1.6.1
Description
The Solace Extra WordPress plugin fails to perform capability or nonce checks in an AJAX action. This allows any authenticated user, including those with subscriber privileges, to update post meta on arbitrary posts and deactivate the active site templates. This can be achieved directly by an authenticated user or via Cross-Site Request Forgery (CSRF), where a logged-in user is tricked into performing the action. The issue is located in the
solace update sitebuilder status action.Recommendations
Update Solace Extra to version 1.6.1 or later.
Exploit
Fix
Missing Authorization
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Solace Extra