Executive brief
The Solace Extra plugin for WordPress, which provides starter templates and site-building tools, contains a security flaw that allows unauthorized users to delete website content. An attacker could permanently remove pages, posts, media, and WooCommerce product data without needing an administrative account. This could lead to significant data loss and disruption of business operations for affected websites.
Technical details
The Solace Extra plugin for WordPress (up to version 1.5.3) is vulnerable to a missing authorization check (CWE-862) in its Starter Template feature. The vulnerability exists because the plugin fails to validate user permissions before executing content deletion actions. Furthermore, the required security nonce is leaked on all administrative pages via wp_localize_script(), and the AJAX handler is registered using wp_ajax_nopriv_, making the functionality accessible to unauthenticated users. Attackers can exploit this to delete posts, pages, media, WooCommerce products, and sitebuilder templates. A patch is available in versions following 1.5.3.
Affected products
- solacewp Solace Extra up to, and including, 1.5.3
Timeline
- 2026-07-11: disclosed
- 2026-07-11: advisory
References
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.1/admin/class-solace-extra-admin.php
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.1/admin/import.php
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.1/includes/class-solace-extra.php
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.3/admin/class-solace-extra-admin.php
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.3/admin/import.php
- https://plugins.trac.wordpress.org/browser/solace-extra/tags/1.5.3/includes/class-solace-extra.php
- https://plugins.trac.wordpress.org/changeset?reponame=&old=3593408%40solace-extra&new=3593408%40solace-extra