CVE-2026-13250
Last modified
CVE-2026-13250 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
The Solace Extra plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.3. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to permanently delete all content previously imported via the Starter Template feature, including posts, pages, media attachments, WooCommerce products, taxonomy terms, and sitebuilder templates. The required nonce is emitted on every wp-admin page via wp_localize_script() hooked to admin_enqueue_scripts without a page guard, meaning any Subscriber visiting /wp-admin/profile.php can obtain it; the handler is additionally registered via wp_ajax_nopriv_, making it reachable by fully unauthenticated users as well.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| solacewp | Solace Extra | <= 1.5.3 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-13250?
How severe is CVE-2026-13250?
How do I fix CVE-2026-13250?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-13243Cross-Site Request Forgery (CSRF) vulnerability in Drupal Sa…4.8
- CVE-2026-13244Improperly Controlled Modification of Dynamically-Determined…8.1
- CVE-2026-13245The MaxButtons – Create buttons plugin for WordPress is vuln…6.1
- CVE-2026-13246The GiveWP – Donation Plugin and Fundraising Platform plugin…6.4
- CVE-2026-13247The Logo Slider – Logo Carousel, Client Logo Slider & Brand …6.4
- CVE-2026-1325A security flaw has been discovered in Sangfor Operation and…9.8
- CVE-2026-13251The Perfmatters plugin for WordPress is vulnerable to Direct…7.5
- CVE-2026-13252The RSS Aggregator by Feedzy – Feed to Post, Autoblogging, N…6.4
- CVE-2026-13253The Ultimate Post plugin for WordPress is vulnerable to Stor…6.4
- CVE-2026-1326A weakness has been identified in Totolink NR1800X 9.1.0u.62…8.8
- CVE-2026-13262The Majestic Support – The Leading-Edge Help Desk & Customer…6.5
- CVE-2026-13268G DATA Total Security Backup Service Link Following Local Pr…7.8
Are you affected by CVE-2026-13250?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
