Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Solace Extra < 1.6.1 - Subscriber+ Multiple Missing Authorization via Site-Wide Nonce Exposure
Vulnerability Description
The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects them on admin pages reachable by low-privileged users, allowing users with a role as low as Subscriber to modify site-wide presentation settings and delete imported site-builder content.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
WordPress Solace Extra 安全漏洞
Vulnerability Description
WordPress Solace Extra是WordPress基金会的一款内容管理系统组件扩展插件。 WordPress Solace Extra 1.6.1之前版本存在安全漏洞,该漏洞源于未执行能力检查并暴露nonce,可能导致低权限用户(如订阅者)修改站点范围演示设置和删除导入的站点构建器内容。
CVSS Information
N/A
Vulnerability Type
N/A