Impact
The Solace Extra WordPress plugin fails to enforce capability and nonce checks on a specific AJAX endpoint. As a result, any authenticated user—including a subscriber—can invoke this action to alter post meta fields on any post. The same flaw also allows attackers to deactivate the site's active templates, effectively disrupting site appearance and functionality. This is a classic case of broken access control that compromises data integrity and availability, potentially allowing an attacker to manipulate content without proper authorization.
Affected Systems
All installations of the Solace Extra WordPress plugin with a version older than 1.6.1 are vulnerable. Users of the plugin should verify their installed version and update if they are running a prior release.
Risk and Exploitability
The vulnerability is exploitable by any logged‑in user; the lack of nonce validation also permits cross‑site request forgery, meaning even users without explicit subscription privileges could be coaxed into performing the action. The CVSS score of 4.3 indicates a low severity, but the nature of the flaw suggests that exploitation could still have operational impacts. The EPSS score of < 1% indicates a low likelihood of exploitation, and the issue is not listed in the CISA KEV catalog, yet the capability to modify arbitrary post metadata and disable templates indicates potential operational disruption.
OpenCVE Enrichment