← WordPress Vulnerabilities
WordPress security by component

Solace Extra

Solace Extra (solace-extra) is a WordPress plugin with 9 published CVE records in this archive. The latest tracked vulnerability was published Sep 02, 2026; the highest published CVSS base score is 9.9.

Plugin slug: solace-extra

CVE-2026-16966: Solace Extra exposes non-public Site Builder content

Solace Extra before 1.7.0 omits authorization and post-status checks from an AJAX action. An unauthenticated visitor can read draft, pending, private, and trashed Site Builder parts that WordPress would not otherwise serve.

PublishedSep 02, 2026
Known safe version1.7.0
Published vulnerabilities for solace-extra
Safe version
Sep 02, 2026 CVE-2026-16966
Solace Extra exposes non-public Site Builder content
Solace Extra before 1.7.0 omits authorization and post-status checks from an AJAX action. An unauthenticated visitor can read draft, pending, private, and trashed Site Builder parts that WordPress would not otherwise serve.
1.7.0
CVE5.3
NVDPending
Aug 16, 2026 CVE-2026-18316
Solace Extra import_zip lets Subscribers erase site configuration
Solace Extra through 1.6.0 registers import_zip() on action-import-zip AJAX hooks and checks only ajax-nonce. That nonce is localized on every admin page without restricting admin_enqueue_scripts, so a Subscriber can obtain it. The attacker can then erase navigation menus, sidebar widgets, all theme modifications and Elementor templates, or trigger arbitrary demo-content imports. The complete import archive format and request parameters are not disclosed.
See mitigation notes
CVE9.1
NVDPending
Aug 13, 2026 CVE-2026-27535
Solace Extra: Broken access control
Solace Extra is affected by broken access control. Exploitation requires an authenticated subscriber account. A successful request can reach data or an operation that should be restricted to another user or a more privileged role. The published affected range is n/a through 1.6.0.
1.6.1
CVE7.1
NVDPending
Aug 09, 2026 CVE-2026-16965
Solace Extra AJAX action lets Subscribers alter post metadata and deactivate templates
Solace Extra before 1.6.1 exposes an AJAX action without capability or nonce checks. Any authenticated user, including a Subscriber, can update post metadata on arbitrary posts and deactivate the site's active templates. Because the action lacks a nonce, an attacker can also induce any logged-in user to submit the request through cross-site request forgery.
1.6.1
CVE4.3
NVDPending
Aug 08, 2026 CVE-2026-16948
Solace Extra AJAX actions let Subscribers alter presentation settings and imported site-builder content
Solace Extra before 1.6.1 protects several admin-ajax.php actions with shared or admin-page nonces but does not enforce an administrator capability. Because low-privileged users can reach pages exposing those nonces, a Subscriber can invoke update_solace_font_and_color, update_logo2, update_sol_color_base_font_elementor_system_color and solace_update_sitebuilder_status with attacker-controlled font, color, logo_url, post_id, status and part values. The callbacks update theme modifications, Elementor kit settings or site-builder post metadata, enabling site-wide presentation changes and destructive changes to imported site-builder content. Version 1.6.1 adds manage_options checks and an action-specific nonce for the site-builder status operation.
1.6.1
CVE8.1
NVDPending
Jul 11, 2026 CVE-2026-13250
Solace Extra: A security weakness
Solace Extra is affected by a security weakness. The vulnerable path is reachable without authentication. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 1.5.3.
See mitigation notes
CVE5.3
NVDPending
Aug 27, 2025 CVE-2025-58203
Solace Extra: Server-side request forgery
Solace Extra is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.4
NVDPending
May 07, 2025 CVE-2025-47464
Solace Extra: Server-side request forgery
Solace Extra is affected by server-side request forgery. Exposure depends on how the affected operation is made reachable by the site. The vulnerable server can be induced to make attacker-selected network requests.
See mitigation notes
CVE4.9
NVDPending
Apr 17, 2025 CVE-2025-32652
Solace Extra: Dangerous file upload
Solace Extra is affected by dangerous file upload. Exposure depends on how the affected operation is made reachable by the site. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise.
See mitigation notes
CVE9.9
NVDPending