
PEACH
Un cadre d’isolation des locataires
CVE-2026-16948 is an authorization bypass vulnerability in the Solace Extra WordPress plugin affecting all versions before 1.6.1. The flaw allows users with a role as low as Subscriber to perform unauthorized administrative actions by exploiting missing capability checks in multiple AJAX actions combined with exposed security nonces on admin pages accessible to low-privileged users. It was publicly disclosed on August 3, 2026, and assigned a CVSS score of 8.1 (High) by WPScan (WPScan, GitHub Advisory).
The root cause is classified as CWE-284 (Improper Access Control) / Broken Access Control (OWASP A5). The plugin fails to validate user capabilities before executing several AJAX actions, and critically, it exposes the WordPress nonce — the token intended to protect these actions — on admin pages that low-privileged users (Subscribers) can access. An authenticated attacker with Subscriber-level access can retrieve the nonce from an accessible admin page and then craft AJAX requests to invoke privileged actions without proper authorization checks (WPScan). The original researcher is JunHee CHO (GitHub: jun2e0).
A successful exploit allows a Subscriber-level authenticated user to modify site-wide presentation settings and delete imported site-builder content without authorization. This threatens both the integrity and availability of the WordPress site, as an attacker could deface the site's appearance or destroy page-builder content. While the vulnerability does not directly enable remote code execution or data exfiltration, unauthorized modification of site settings could be leveraged for defacement or as a stepping stone in a broader attack (WPScan, GitHub Advisory).
There is currently no public proof-of-concept exploit available; WPScan has indicated the PoC will be disclosed on September 10, 2026, to allow time for users to update. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The EPSS score is approximately 0.00132, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog (WPScan, GitHub Advisory).
/wp-admin/admin-ajax.php) with the appropriate action parameter corresponding to one of the vulnerable Solace Extra AJAX handlers, including the extracted nonce./wp-admin/admin-ajax.php with Solace Extra-specific action parameters outside of normal usage patterns./wp-admin/admin-ajax.php from a single low-privileged user account in a short time window.wp_options table, or missing site-builder content/posts that were previously present.Update the Solace Extra WordPress plugin to version 1.6.1 or later, which introduces proper capability checks in the affected AJAX actions (WPScan). If immediate patching is not possible, consider temporarily deactivating the plugin to eliminate the attack surface. After patching, review site-wide presentation settings and site-builder content for any unauthorized modifications made by low-privileged users, and audit user roles to ensure Subscriber accounts are limited to trusted individuals.
A brief mention of the vulnerability was noted on Mastodon (infosec.exchange) shortly after disclosure, consistent with routine community tracking of WordPress plugin vulnerabilities. No significant vendor statements, major media coverage, or notable researcher commentary beyond the original WPScan report and researcher submission by JunHee CHO have been identified (WPScan).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."