CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-16948

unknowncovered by 1 sourcefirst seen 2026-08-08
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.

⚡ Watch CVE-2026-16948

Get an email if CVE-2026-16948 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-16948

CVE.org record

Embed the live status

CVE-2026-16948 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-16948 status](https://www.csirts.com/badge/CVE-2026-16948)](https://www.csirts.com/cve/CVE-2026-16948)