WordPress Plugin Vulnerabilities

Solace Extra < 1.6.1 - Subscriber+ Post Meta Update via solace_update_sitebuilder_status

Description

The plugin does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.

Proof of Concept

Affects Plugins

Fixed in 1.6.1

References

Classification

Type
NO AUTHORISATION
CWE

Miscellaneous

Original Researcher
JunHee CHO
Submitter
JunHee CHO
Submitter website
Verified
Yes

Timeline

Publicly Published
2026-08-03 (about 27 days ago)
Added
2026-08-03 (about 26 days ago)
Last Updated
2026-08-03 (about 26 days ago)

Other