CyberRota Analysis
AI-GeneratedThe Solace Extra WordPress plugin prior to version 1.7.0 is vulnerable due to a lack of authorization checks in its AJAX actions, enabling unauthenticated users to access non-published content such as drafts and private posts. This exposure can lead to unauthorized information disclosure, potentially compromising sensitive site data. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The Solace Extra WordPress plugin before 1.7.0 does not perform any authorization or post-status checks in one of its AJAX actions, allowing unauthenticated visitors to read the content of non-published (draft, pending, private, and trashed) Site Builder parts that WordPress would otherwise not serve.