---
id: CVE-2026-80333
title: >-
  The Solace Extra WordPress plugin before 1.7.2 does not perform any
  authorization or post-status checks on its front-end preview routes, allowing
  unauthenticated visitors to read the rendered content of non-published posts
  and pages of a…
summary: >-
  The Solace Extra WordPress plugin before 1.7.2 does not perform any
  authorization or post-status checks on its front-end preview routes, allowing
  unauthenticated visitors to read the rendered content of non-published posts
  and pages of a…
severity: none
cwe:
  - CWE-200
product: Solace Extra
affected:
  - solace_extra < 1.7.2
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:05.003'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-80333'
references:
  - url: 'https://wpscan.com/vulnerability/2baffcd4-686e-40db-96b3-5abc70a03a5f/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.550Z'
---

## Overview

The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
