SolaPlugins Sola Support Ticket Missing Authorization Vulnerability Allowing Arbitrary Content Deletion

Vulnerability

A missing authorization vulnerability has been identified in the Sola Support Ticket plugin by SolaPlugins, affecting versions through 3.17. This vulnerability allows for the exploitation of improperly configured access control security levels, potentially leading to arbitrary content deletion on affected WordPress sites.

Impact

Exploitation of this vulnerability could result in the unauthorized deletion of content, such as posts, pages, or media, from the WordPress site.

Remediation

Users are advised to remove and replace the Sola Support Ticket plugin, as it is likely abandoned and will not receive further updates or fixes.

Added: Jun 6, 2025, 3:15 PM
Updated: Jun 6, 2025, 3:15 PM

Vulnerability Rating

Custom Algorithm
spread
1.0
impact
0.6
exploitability
5.4
remediation
0.0
relevance
0.1
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.