{"id":"CVE-2026-80333","title":"The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of a…","summary":"The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of a…","severity":"none","cwe":["CWE-200"],"product":"Solace Extra","affected":["solace_extra < 1.7.2"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:05.003","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-80333","references":[{"url":"https://wpscan.com/vulnerability/2baffcd4-686e-40db-96b3-5abc70a03a5f/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.550Z","slug":"CVE-2026-80333","body":"## Overview\n\nThe Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}