CVE-2026-18316 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 16:07pm

A security flaw has been found in the Solace Extra plugin for WordPress, affecting all versions up to and including 1.6.0. The plugin does not properly check if a user has the correct permissions to run its import function, which means even users with very basic access to your site's backend (such as Subscribers, the lowest-level role for logged-in site visitors) can use this function without authorization.

If exploited, this flaw lets an attacker with even this basic level of access delete or overwrite key parts of your site. This includes your navigation menus, sidebar widgets, all customizations you have made to your site's theme (such as layout, colors, and branding changes), Elementor page templates you have built, and can even trigger unwanted imports of demo content that disrupts your site's existing content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18316

« Back