CVE-2026-80333: Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes
Published Sep 30, 2026
·Updated
The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.
Affected Software
1 affected component
Solace Solace Extra<1.7.2
Event History
Sep 30, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Data Sourced
via NVD·06:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Any unauthenticated visitor can exploit the affected front-end preview routes. No login or WordPress role is required.
2
What content may be exposed?
Rendered content from non-published posts and pages may be disclosed, including content types that WordPress would not normally serve to visitors.
3
Are published posts required for exploitation?
No. The issue specifically affects non-published content because the routes do not enforce post-status checks.