Solace Extra
Solace Extra has 10 disclosed vulnerabilities in the WordSec catalog, reported between 2025 and 2026; all 10 are fixed as of September 2026. Their average CVSS score is 6.3, and the most serious one scores 9.1 out of 10. Severity breakdown: 1 critical and 2 high. 2026 was the busiest year with 6 disclosures.
The most common weakness is Missing Authorization, behind 5 of the records (50%). Other recurring categories include Server-Side Request Forgery (SSRF), Unrestricted Upload Of File With Dangerous Type.
Every one of the 10 issues recorded for Solace Extra has a vendor fix available, so running the current release closes all known holes.
7 independent researchers contributed these findings, most of them (3) reported by JunHee CHO. Solace Extra is installed on roughly 10,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.
CVE-2026-18316Solace Extra <= 1.6.0 - Missing Authorization to Unauthenticated Site Content Deletion and Unauthorized Demo Import via action-import-zip AJAX Action
Read the full analysisVulnerability Records

Solace Extra
Author
solacewp
The Solace Extra plugin is designed to enhance the user experience for Solace Theme users by facilitating the selection and importation of pre-designed Elementor templates. With this plugin, users can effortlessly browse through a variety of templates and seamlessly import them into their WordPress website, simplifying the process of building stunning pages with Elementor. This plugin uses external services provided by SolaceWP and Google reCAPTCHA. These services include fetching demo content, retrieving plugin information, and providing security features to prevent spam and abuse. Data will be sent to and retrieved from https://solacewp.com/api (which is operated by the plugin author) and https://www.google.com/recaptcha. For more details, please refer to the service terms of use and privacy policies: – SolaceWP: Terms of Use, Privacy Policy – Google reCAPTCHA: Terms of Use, Privacy Policy – Sendy API: Terms of Use, Privacy Policy
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C