Product
The Solace Extra plugin for WordPress (<= 1.6.0) contains a broken access control vulnerability in the import_zip() function that allows authenticated users to delete critical theme settings and content.