The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip() function in versions up to, and including, 1.6.0. The handler is registered on both wp_ajax_action-import-zip and wp_ajax_nopriv_action-import-zip and only verifies the 'ajax-nonce' nonce, which is emitted on every admin page via wp_localize_script (unrestricted admin_enqueue_scripts hook) and is therefore accessible to any authenticated user including Subscribers. This makes it possible for authenticated attackers, with Subscriber-level access and above, to wipe navigation menus, sidebar widgets (via update_option('sidebars_widgets', array())), all theme mods (via remove_theme_mods()), and Elementor templates, as well as trigger arbitrary demo-content imports.
We have discovered 497 live websites that are affected by CVE-2026-18316.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 497 live websites (98% of Solace Extra install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 8 versions ( 89% of all versions) |
| 185 websites | |
| 60 websites | |
| 40 websites | |
| 28 websites | |
| 15 websites | |
| 15 websites | |
| 15 websites | |
| 11 websites | |
| 10 websites | |
| 8 websites |
| .com | 278 websites |
| .org | 31 websites |
| .co.uk | 19 websites |
| .net | 13 websites |
| .de | 12 websites |
| .nl | 10 websites |
| .com.au | 10 websites |
| .ca | 6 websites |
| .be | 5 websites |
| .es | 5 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | ***,*** | ||
| *****.org | *,***,*** | ||
| ********************.com | *,***,*** | ||
| ************.***.hn | *,***,*** | ||
| ********.com | *,***,*** | ||
| *********.com | *,***,*** | ||
| **********.org | *,***,*** | ||
| **********.com | *,***,*** | ||
| ****************.com | *,***,*** | ||
| ****.amsterdam | *,***,*** |
FAQ