What is CVE-2026-18316?
This is a critical vulnerability discovered in the Solace Extra plugin for WordPress. Due to a missing capability check on the import_zip() function, an unauthenticated attacker can cause unauthorized data modification and loss in versions up to and including 1.6.0. Updating to the latest plugin version is recommended.
Azərbaycanca: Bu, WordPress üçün Solace Extra plaginində aşkarlanan kritik zəiflikdir. import_zip() funksiyasında yoxlanış olmadığı üçün autentifikasiyasız hücumçu plaginin 1.6.0 və daha əvvəlki versiyalarına təsir edərək icazəsiz məlumat dəyişikliyi və itkisinə səbəb ola bilər. Plaginin ən son versiyasına yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
What is the CVE-2026-18316 vulnerability?
It is a critical vulnerability discovered in the Solace Extra plugin for WordPress. It exists in versions up to and including 1.6.0.
How to protect against CVE-2026-18316?
Updating the Solace Extra plugin to the latest version is recommended.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.