Impact
The Solace Extra WordPress plugin contains several AJAX actions that do not verify the user’s permissions before executing. In addition, the nonce used to protect these actions is displayed on admin pages that low‑privileged users can access. Because the plugin is vulnerable in all versions prior to 1.6.1, an attacker who can become a Subscriber—or any user with a role no higher than Subscriber—can send crafted AJAX requests that modify site‑wide presentation settings or delete content created by a site‑builder. Consequently, the attacker can compromise the integrity of the site and disrupt normal operation, effectively acting as a host‑level privilege escalation. There is no need for additional credentials beyond a low‑privileged account.
Affected Systems
WordPress sites that have the Solace Extra plugin installed, any version older than 1.6.1. The only vendor mentioned is Unknown:Solace Extra, which indicates the plugin is likely developed by an independent or internal team. All installations using these vulnerable versions are at risk.
Risk and Exploitability
Because the vulnerability can be exploited by any user with a Subscriber role, no external network attack or directed privilege escalation is required; a local account with minimal privileges suffices. While the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, the lack of capability checks combined with exposed nonces presents a high exploitation likelihood within sites that use the vulnerable plugin. The CVSS score is not provided, but the impact and access requirements suggest that exploitation could be achieved with relative ease once a low‑privileged user is present on the site.
OpenCVE Enrichment