VYPR

Solace Extra

by WordPress

Source repositories

CVEs (9)

  • CVE-2025-32652CriApr 17, 2025
    risk 0.64cvss 9.9epss 0.00

    Unrestricted Upload of File with Dangerous Type vulnerability in solacewp Solace Extra solace-extra allows Using Malicious Files.This issue affects Solace Extra: from n/a through <= 1.3.1.

  • CVE-2026-16948HigAug 8, 2026
    risk 0.53cvss 8.1epss 0.00

    The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide…

  • CVE-2026-18316CriAug 16, 2026
    risk 0.52cvss 9.1epss 0.00

    The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and…

  • CVE-2026-27535HigAug 13, 2026
    risk 0.46cvss 7.1epss 0.00

    Subscriber Broken Access Control in Solace Extra <= 1.6.0 versions.

  • CVE-2026-16966MedSep 2, 2026
    risk 0.34cvss 5.3epss 0.00

    The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress…

  • CVE-2025-47464MedMay 7, 2025
    risk 0.32cvss 4.9epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forgery.This issue affects Solace Extra: from n/a through <= 1.3.1.

  • CVE-2025-58203MedAug 27, 2025
    risk 0.29cvss 4.4epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in solacewp Solace Extra solace-extra allows Server Side Request Forgery.This issue affects Solace Extra: from n/a through <= 1.3.2.

  • CVE-2026-16965MedAug 9, 2026
    risk 0.28cvss 4.3epss 0.00

    The Solace Extra WordPress plugin before 1.6.1 does not perform capability or nonce checks in one of its AJAX actions, allowing any authenticated user such as a subscriber (and, via CSRF, any logged-in user) to update post meta on arbitrary posts and to deactivate the site's…

  • CVE-2026-13250MedJul 11, 2026
    risk 0.00cvss 5.3epss 0.00

    The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to…