What is CVE-2026-16965?
The Solace Extra WordPress plugin before version 1.6.1 lacks capability and nonce checks in an AJAX action, enabling any authenticated user (e.g., subscriber) or any logged-in user via CSRF to update post meta on arbitrary posts and deactivate active templates. Immediate update to the latest version is recommended.
Azərbaycanca: Solace Extra WordPress plaginində (1.6.1-dən əvvəlki versiyalarda) AJAX əməliyyatında icazə (capability) və nonce yoxlaması olmadığı üçün autentifikasiya olunmuş istənilən istifadəçi (məsələn, abunəçi) və ya CSRF vasitəsilə istənilən daxil olmuş istifadəçi paylaşımların meta məlumatlarını yeniləyə, aktiv şablonları deaktiv edə bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
My site has Solace Extra plugin version 1.6.0 installed. Which users can make unauthorized changes using the CVE-2026-16965 vulnerability?
Any authenticated user (e.g., subscriber), as well as any logged-in user via CSRF.
What causes the CVE-2026-16965 vulnerability and how to fix it?
The vulnerability occurs due to missing capability and nonce checks in an AJAX action. An immediate update to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.