Impact
The Solace Extra WordPress plugin fails to enforce authorization on the AJAX action used to retrieve Site Builder content. This oversight allows any web visitor, without authentication, to request and receive the HTML of components that are stored as drafts, pending, private, or trashed, which WordPress normally protects from unauthenticated users. The primary impact is the disclosure of potentially confidential or sensitive design data to anyone with internet access, compromising confidentiality of unpublished content.
Affected Systems
This vulnerability affects installations of the Solace Extra plugin, version 1.6.x and earlier. The attack requires the plugin to be active on a WordPress site; no other product or platform version information is indicated.
Risk and Exploitability
The EPSS score of <1% indicates a very low likelihood of public exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. No authentication is required, and an attacker can simply send a crafted AJAX request to the get_elementor_content endpoint to retrieve the content of draft, pending, private, or trashed Site Builder parts. A CVSS score of 5.3 indicates moderate risk; the unauthorized disclosure of unpublished content could compromise confidentiality, especially if the drafts contain sensitive or proprietary data.
OpenCVE Enrichment