
🚨*CVE* CVE-2026-16948 The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pag… https://www.cve.org/CVERecord?id=CVE-2026-16948 ----- Traducción: CVE-2026-16948 El … http://infoflow.cloud`
Post summary
The message notes that CVE-2026-16948 is a vulnerability in Solace Extra’s WordPress plugin (pre‑1.6.1) where capability checks are missing on AJAX actions, exposing the nonce.


