Beveiligingsadvies

CVE-2026-16965

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-09 06:00:11
Laatst bijgewerkt 2026-08-11 19:43:41
Toegewezen door WPScan
CVSS-score 4.3
Status PUBLISHED

Beschrijving

The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's active templates.