๐Ÿ” CVE Alert

CVE-2026-80333

UNKNOWN 0.0

Solace Extra < 1.7.2 - Unauthenticated Non-Published Post Content Disclosure via Preview Routes

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Solace Extra WordPress plugin before 1.7.2 does not perform any authorization or post-status checks on its front-end preview routes, allowing unauthenticated visitors to read the rendered content of non-published posts and pages of any type that WordPress would otherwise not serve.

Vendor unknown
Product solace extra
Published Sep 30, 2026
Stay Ahead of the Next One

Get instant alerts for unknown solace extra

Be the first to know when new unknown vulnerabilities affecting unknown solace extra are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Solace Extra
0 < 1.7.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/2baffcd4-686e-40db-96b3-5abc70a03a5f/

Credits

Erwan LR (WPScan) WPScan