A security flaw has been identified in the Solace Extra plugin for WordPress, affecting all versions up to and including 1.6.0. The issue comes from a missing permission check that allows any logged-in user on your site, even those with only basic subscriber access (the lowest level of user permission), to perform unauthorized actions.
Attackers with this low-level access can wipe your site's navigation menus, delete all sidebar widgets, erase your custom theme adjustments, remove Elementor page templates, and trigger unrequested demo content imports that can damage or erase your site's content and core settings.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-18316