SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-16966

MEDIUM · CVSS 5.3 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Solace Extra WordPress plugin prior to version 1.7.0 is vulnerable due to a lack of authorization checks in its AJAX actions, enabling unauthenticated users to access non-published content such as drafts and private posts. This exposure can lead to unauthorized information disclosure, potentially compromising sensitive site data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-16966
Severity
MEDIUM
CVSS
5.3
EPSS
0.24%
WordPress

Original NVD Description

The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve.