Soledad [soledad] <= 8.7.2 (unfixed)
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad soledad allows DOM-Based XSS.This issue affects Soledad: from n/a through <= 8.7.2.
- Affected:
- up to 8.7.2
- Fix:
- No patched version reported
- Disclosed:
- Feb 19, 2026
CVE-2026-27069 on NVD →
Soledad <= 8.7.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.7.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 8.7.2
- Fix:
- No patched version reported
- Disclosed:
- Jan 10, 2026
CVE-2026-27069 on NVD →
Soledad [soledad] <= 8.6.9 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9.
- Affected:
- up to 8.6.9
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-64188 on NVD →
Soledad [soledad] <= 8.7.0 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects Soledad: from n/a through <= 8.7.0.
- Affected:
- up to 8.7.0
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-68066 on NVD →
Soledad <= 8.7.0 - Authenticated (Contributor+) Local File Inclusion
high
The Soledad theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.7.0. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This ca...
- CVSS:
- 7.5
- Affected:
- up to 8.7.0
- Fix:
- No patched version reported
- Disclosed:
- Oct 28, 2025
CVE-2025-68066 on NVD →
Soledad < = 8.6.9 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Options Update
high
The Soledad theme for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'penci_update_option' function in all versions up to, and including, 8.6.9. This makes it possible for authenticated attackers, with Subscriber-level access a...
- CVSS:
- 8.8
- Affected:
- up to 8.6.9
- Fixed in:
- 8.6.9.1
- Disclosed:
- Oct 23, 2025
CVE-2025-64188 on NVD →
Soledad <= 8.6.8 - Authenticated (Contributor+) Local File Inclusion
high
The Soledad theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 8.6.8. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This ca...
- CVSS:
- 7.5
- Affected:
- up to 8.6.8
- Fixed in:
- 8.6.9
- Disclosed:
- Sep 22, 2025
CVE-2025-59588 on NVD →
Soledad <= 8.6.8 - Authenticated (Contributor+) Stored Cross-Site Scripting
medium
The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 8.6.8 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will...
- CVSS:
- 6.4
- Affected:
- up to 8.6.8
- Fixed in:
- 8.6.9
- Disclosed:
- Sep 22, 2025
CVE-2025-59589 on NVD →
Soledad <= 8.6.7 - Authenticated (Contributor+) Local File Inclusion via 'header_layout'
high
The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to include and execute arbitrary .php files on the server, allowing the execut...
- CVSS:
- 8.8
- Affected:
- up to 8.6.7
- Fixed in:
- 8.6.8
- Disclosed:
- Aug 15, 2025
CVE-2025-8142 on NVD →
Soledad <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution
high
The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for unauthenticated attackers to exe...
- CVSS:
- 7.3
- Affected:
- up to 8.6.7
- Fixed in:
- 8.6.8
- Disclosed:
- Aug 15, 2025
CVE-2025-8105 on NVD →
Soledad <= 8.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h'
medium
The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘pcsml_smartlists_h’ parameter in all versions up to, and including, 8.6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inje...
- CVSS:
- 6.4
- Affected:
- up to 8.6.7
- Fixed in:
- 8.6.8
- Disclosed:
- Aug 15, 2025
CVE-2025-8143 on NVD →
Soledad [soledad] < 8.6.0
unknown
[en] The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, and penci_more_featured_post_ajax_func. This makes it possible for unauthenticated attackers to include and exec...
- Affected:
- up to 8.6.0
- Fixed in:
- 8.6.0
- Disclosed:
- Dec 6, 2024
CVE-2024-11289 on NVD →
Soledad <= 8.5.9 - Unauthenticated Limited Local File Inclusion
high
The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penci_more_post_ajax_func, and penci_more_featured_post_ajax_func. This makes it possible for unauthenticated attackers to include and execute P...
- CVSS:
- 8.1
- Affected:
- up to 8.5.9
- Fixed in:
- 8.6.0
- Disclosed:
- Dec 5, 2024
CVE-2024-11289 on NVD →
Soledad <= 8.4.5 - Missing Authorization
medium
The Soledad theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.4.5. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 8.4.5
- Fixed in:
- 8.4.6
- Disclosed:
- Apr 9, 2024
CVE-2024-31368 on NVD →
Soledad <= 8.4.5 - Cross-Site Request Forgery
medium
The Soledad theme for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 8.4.5. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action via a forged request granted they can trick a si...
- CVSS:
- 4.3
- Affected:
- up to 8.4.5
- Fixed in:
- 8.4.6
- Disclosed:
- Apr 9, 2024
CVE-2024-31369 on NVD →
Soledad <= 8.4.5 - Missing Authorization
medium
The Soledad theme for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 8.4.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.
- CVSS:
- 4.3
- Affected:
- up to 8.4.5
- Fixed in:
- 8.4.6
- Disclosed:
- Apr 9, 2024
CVE-2024-31367 on NVD →
Soledad [soledad] < 8.4.6
unknown
[en] Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
- Affected:
- up to 8.4.6
- Fixed in:
- 8.4.6
- Disclosed:
- Apr 9, 2024
CVE-2024-31368 on NVD →
Soledad [soledad] < 8.4.6
unknown
[en] Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
- Affected:
- up to 8.4.6
- Fixed in:
- 8.4.6
- Disclosed:
- Apr 9, 2024
CVE-2024-31367 on NVD →
Soledad [soledad] < 8.4.6
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
- Affected:
- up to 8.4.6
- Fixed in:
- 8.4.6
- Disclosed:
- Apr 9, 2024
CVE-2024-31369 on NVD →
Soledad [soledad] < 8.4.2
unknown
[en] Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.
- Affected:
- up to 8.4.2
- Fixed in:
- 8.4.2
- Disclosed:
- Dec 21, 2023
CVE-2023-49826 on NVD →
Soledad [soledad] < 8.4.2
unknown
[en] Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.
- Affected:
- up to 8.4.2
- Fixed in:
- 8.4.2
- Disclosed:
- Dec 20, 2023
CVE-2023-49825 on NVD →
Soledad [soledad] < 8.4.2
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4...
- Affected:
- up to 8.4.2
- Fixed in:
- 8.4.2
- Disclosed:
- Dec 14, 2023
CVE-2023-49827 on NVD →
Soledad <= 8.4.1 - Unauthenticated PHP Object Injection
critical
The Soledad theme for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 8.4.1 via deserialization of untrusted input. This makes it possible for unauthenticated attackers to inject a PHP Object. No POP chain is present in the vulnerable theme. If a POP chain is present via an additio...
- CVSS:
- 9.8
- Affected:
- up to 8.4.1
- Fixed in:
- 8.4.2
- Disclosed:
- Dec 5, 2023
CVE-2023-49826 on NVD →
Soledad <= 8.4.1 - Authenticated (Contributor+) SQL Injection
high
The Soledad theme for WordPress is vulnerable to SQL Injection in versions up to, and including, 8.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, t...
- CVSS:
- 8.8
- Affected:
- up to 8.4.1
- Fixed in:
- 8.4.2
- Disclosed:
- Dec 5, 2023
CVE-2023-49825 on NVD →
Soledad <= 8.4.1 - Reflected Cross-Site Scripting
medium
The Soledad theme for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 8.4.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a...
- CVSS:
- 6.1
- Affected:
- up to 8.4.1
- Fixed in:
- 8.4.2
- Disclosed:
- Dec 5, 2023
CVE-2023-49827 on NVD →
Soledad [soledad] < 8.2.6
unknown
[en] Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Soledad premium theme <= 8.2.5 on WordPress.
- Affected:
- up to 8.2.6
- Fixed in:
- 8.2.6
- Disclosed:
- Nov 18, 2022
CVE-2022-41788 on NVD →
Soledad <= 8.2.5 - Missing Authorization
medium
The Soledad plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on one of its functions in versions up to, and including, 8.2.5. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function that was not intended for the...
- CVSS:
- 5.4
- Affected:
- up to 8.2.5
- Fixed in:
- 8.2.6
- Disclosed:
- Nov 1, 2022
CVE-2022-42479 on NVD →
Soledad <= 8.2.5 - Authenticated (Subscriber+) Cross-Site Scripting
medium
The Soledad theme for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 1.4 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to inject arbitrary web scripts in pages that wi...
- CVSS:
- 6.4
- Affected:
- up to 8.2.5
- Fixed in:
- 8.2.6
- Disclosed:
- Oct 30, 2022
CVE-2022-41788 on NVD →
Soledad [soledad] < 8.2.5
unknown
[en] The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.
- Affected:
- up to 8.2.5
- Fixed in:
- 8.2.5
- Disclosed:
- Oct 10, 2022
CVE-2022-3209 on NVD →
Soledad <= 8.2.4 - Reflected Cross-Site Scripting
medium
The Soledad plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘id’ parameter among others in versions up to, and including, 8.2.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that exe...
- CVSS:
- 6.1
- Affected:
- up to 8.2.4
- Fixed in:
- 8.2.5
- Disclosed:
- Sep 13, 2022
CVE-2022-3209 on NVD →
Soledad [soledad] < 8.2.6
unknown
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
- Affected:
- up to 8.2.6
- Fixed in:
- 8.2.6
CVE-2022-42479 on NVD →
Soledad [soledad] < 8.6.8
unknown
- Affected:
- up to 8.6.8
- Fixed in:
- 8.6.8
CVE-2025-8105 on NVD →
Soledad [soledad] < 8.6.8
unknown
- Affected:
- up to 8.6.8
- Fixed in:
- 8.6.8
CVE-2025-8143 on NVD →
Soledad [soledad] < 8.6.8
unknown
- Affected:
- up to 8.6.8
- Fixed in:
- 8.6.8
CVE-2025-8142 on NVD →
Soledad [soledad] < 8.6.9
unknown
- Affected:
- up to 8.6.9
- Fixed in:
- 8.6.9
CVE-2025-59589 on NVD →