CVE-2026-18316 (matched: wordpress)

  • Sunday, 16th August, 2026
  • 22:06pm

A security flaw has been found in the Solace Extra plugin for WordPress, affecting all versions up to and including 1.6.0. The issue comes from a missing permission check that lets even low-level logged-in users (such as Subscribers, who normally only have read-only access to your site) run restricted site actions they are not supposed to be able to perform.

If exploited, this flaw allows attackers with this basic level of site access to delete your navigation menus, erase sidebar widgets, wipe all custom theme settings, delete Elementor page templates, or run unapproved demo content imports that can overwrite your existing site content.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18316

« Back