CVE-2026-16948Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-08-08: 3Technical Details · 2026-08-08: 308-08
Signal classification1 categories
Disclosure
3100.0%
Referenced assets2 URLs
By indicator
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-16948 The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pag… https://www.cve.org/CVERecord?id=CVE-2026-16948 ----- Traducción: CVE-2026-16948 El … http://infoflow.cloud`

    Post summary

    The message notes that CVE-2026-16948 is a vulnerability in Solace Extra’s WordPress plugin (pre‑1.6.1) where capability checks are missing on AJAX actions, exposing the nonce.

    0000096
    98 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-16948 The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pag… https://www.cve.org/CVERecord?id=CVE-2026-16948

    Post summary

    The CVE involves inadequate capability checks in the Solace Extra WordPress plugin’s AJAX actions, exposing a nonce, but no PoC, exploit code, patch, or active exploitation is detailed.

    000001.8K
    57.9K followersView on X
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🌐 WordPress Solace Extra privilege flaw disclosed CVE-2026-16948 affects the Solace Extra plugin before 1.6.1. Insufficient capability checks can allow even Subscriber-level users to modify site-wide presentation settings or delete imported site-builder content. 🔎 Source: WPScan / CVE disclosure #WordPress #WebSecurity #CVE #CyberSecurity

    Post summary

    The post announces a privilege‑escalation flaw (CVE-2026-16948) in WordPress Solace Extra that lets Subscriber users modify site settings and delete content, impacting versions before 1.6.1.

    0000038
    34 followersView on X

Explore more