Broken Access Control Vulnerability in Solace Extra by WordPress
CVE-2026-27535
7.1HIGH
What is CVE-2026-27535?
The Solace Extra WordPress plugin, in versions 1.6.0 and earlier, is vulnerable to broken access control. This flaw allows unauthorized subscribers to potentially access restricted functionalities or perform actions that should be reserved for higher-privileged users. It is crucial for users of this plugin to identify the risk and implement necessary security measures.
Affected Version(s)
Solace Extra <= 1.6.0
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Dahmani Toumi (pega_SUS) | Patchstack Bug Bounty Program