CVE-2026-18316 (matched: wordpress)

  • Monday, 17th August, 2026
  • 04:06am

A security flaw has been identified in the Solace Extra plugin for WordPress, impacting all versions up to and including 1.6.0. The issue stems from a missing permission check on the plugin's import tool, which allows any logged-in user on your WordPress site — even those with the lowest-level "Subscriber" access — to modify or delete critical parts of your site.

Attackers with this basic account access can erase your site's navigation menus, sidebar widgets, custom design settings, and Elementor page templates, or force unrequested demo content imports that can break your site's layout and clutter your content. The plugin's import tool only checks for a standard WordPress verification code that is visible to all logged-in users, rather than confirming the person using it has proper administrative permissions.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18316

« Back