What is CVE-2026-16948?
CVE-2026-16948 affects Solace Extra WordPress plugin versions prior to 1.6.1. The vulnerability allows low-privileged users, such as Subscribers, to modify site-wide presentation settings due to missing capability checks and exposed nonces in AJAX actions. Users should upgrade to the latest version.
Azərbaycanca: CVE-2026-16948, Solace Extra WordPress plagininin 1.6.1-dən əvvəlki versiyalarında aşkar edilib. Bu boşluq Subscriber kimi aşağı imtiyazlı istifadəçilərə saytın təqdimat parametrlərini dəyişməyə imkan verir. Plaginin ən son versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which plugin is affected by CVE-2026-16948?
This vulnerability affects the Solace Extra WordPress plugin in versions prior to 1.6.1.
What can a user with the Subscriber role do by exploiting CVE-2026-16948?
A low-privileged user like a Subscriber can modify site-wide presentation settings.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.