Impact
The Solace Extra WordPress plugin fails to enforce authorization on the AJAX action used to retrieve Site Builder content. This oversight allows any web visitor, without authentication, to request and receive the HTML of components that are stored as drafts, pending, private, or trashed, which WordPress normally protects from unauthenticated users. The primary impact is the disclosure of potentially confidential or sensitive design data to anyone with internet access, compromising confidentiality of unpublished content.
Affected Systems
This vulnerability affects installations of the Solace Extra plugin, version 1.6.x and earlier. The attack requires the plugin to be active on a WordPress site; no other product or platform version information is indicated.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. The lack of an authentication check makes the attack trivial for an unauthenticated attacker simply by sending a crafted AJAX request to the get_elementor_content endpoint. While the CVSS score is not provided, the nature of the flaw—unauthenticated read of non‑published content—indicates a moderate to high confidentiality risk, especially if the drafts contain proprietary or sensitive material.
OpenCVE Enrichment