Impact
The Solace Extra WordPress plugin fails to enforce capability and nonce checks on a specific AJAX endpoint. As a result, any authenticated user—including a subscriber—can invoke this action to alter post meta fields on any post. The same flaw also allows attackers to deactivate the site's active templates, effectively disrupting site appearance and functionality. This is a classic case of broken access control that compromises data integrity and availability, potentially allowing an attacker to manipulate content without proper authorization.
Affected Systems
All installations of the Solace Extra WordPress plugin with a version older than 1.6.1 are vulnerable. Users of the plugin should verify their installed version and update if they are running a prior release.
Risk and Exploitability
The vulnerability is exploitable by any logged‑in user; the lack of nonce validation also permits cross‑site request forgery, meaning even users without explicit subscription privileges could be coaxed into performing the action. While a specific CVSS score is not provided, the nature of the flaw suggests high severity. No EPSS score is available, and the issue is not currently listed in the CISA KEV catalog, but the capability to modify arbitrary post metadata and disable templates indicates that exploitation could have serious operational impacts.
OpenCVE Enrichment