A security vulnerability has been found in the Solace Extra plugin for WordPress, which impacts all versions of the plugin up to and including 1.6.0. The flaw occurs because the plugin does not properly check that users have the correct permissions to run a key data import feature. This permission check is accessible to any user logged into your site's private admin area, even those with the most basic access level (called Subscribers, who usually only have permission to leave comments on your site). If exploited, this flaw lets attackers delete your site's navigation menus, sidebar content, custom theme adjustments, Elementor page templates, and run unapproved bulk content imports that can overwrite or erase your existing site data.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18316