Pencidesign develops the Soledad web application platform, a narrowly scoped product portfolio that serves design and content-management use cases. Vulnerabilities affecting the vendor skew toward serious outcomes, concentrating in application-layer input-handling and authorization weaknesses including cross-site scripting, SQL injection, missing authorization controls, CSRF, and untrusted deserialization that are characteristic of server-side web applications. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pencidesign over time
Signals from CVEs in this vendor scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8142HIGH The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for auth | Aug 16, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-64188CRITICAL Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9. | Dec 18, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-49826CRITICAL Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, News | Dec 21, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-8105HIGH The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execut | Aug 16, 2025 | 7.3 | 26 | NO | NO |
CVE-2024-11289HIGH The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penc | Dec 6, 2024 | 8.1 | 26 | NO | NO |
CVE-2025-68066HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion | Dec 16, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-59588HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion | Sep 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2023-49825HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Th | Dec 20, 2023 | 8.1 | 23 | NO | NO |
CVE-2025-59589MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad soledad allows DOM-Based XSS.This issue affects Soledad: f | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2022-3209MEDIUM The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site | Oct 10, 2022 | 6.1 | 22 | NO | NO |
Signals from CVEs in this vendor scope (17 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pencidesign.
Media articles that mention a CVE ID that affects a product developed by Pencidesign — matched by CVE ID, not by vendor name.