AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-16965

MEDIUM · CVSS 4.3 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-08-09 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Solace Extra WordPress plugin prior to version 1.6.1 is vulnerable due to a lack of capability and nonce checks in its AJAX actions, enabling any authenticated user, including subscribers, to modify post metadata and deactivate active templates on the site. This vulnerability poses a significant risk as it allows unauthorized changes to site content and functionality, potentially leading to site compromise. WordPress site administrators and developers using this plugin should prioritize updating to the latest version to mitigate these risks.

CVE
CVE-2026-16965
Severity
MEDIUM
CVSS
4.3
EPSS
0.10%
WordPress

Original NVD Description

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.