Soledad
Vendor:
First CVE: Oct 10, 2022 · Active for 3 years
17
Total CVEs
More Total CVEs than 93% of tracked products
3.4
Avg CVEs / Year
Higher CVE frequency than 82% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 45% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Soledad over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 10, 2022
3 years ago
Most Recent CVE
Feb 19, 2026
155 days ago
CVE Severity & Scoring
Soledad17 CVEs
47%
41%
12%
All CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network17 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (82.4%)
High3 (17.6%)
Unknown0 (0.0%)
User Interaction
None11 (64.7%)
Unknown0 (0.0%)
Required6 (35.3%)
Privileges Required
Low9 (52.9%)
High0 (0.0%)
None8 (47.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (17 CVEs).
17 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8142HIGH The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.6.7 via the 'header_layout' parameter. This makes it possible for auth | Aug 16, 2025 | 8.8 | 30 | NO | NO |
CVE-2025-64188CRITICAL Incorrect Privilege Assignment vulnerability in PenciDesign Soledad soledad allows Privilege Escalation.This issue affects Soledad: from n/a through <= 8.6.9. | Dec 18, 2025 | 9.8 | 29 | NO | NO |
CVE-2023-49826CRITICAL Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, News | Dec 21, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-8105HIGH The The Soledad theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 8.6.7. This is due to the software allowing users to execut | Aug 16, 2025 | 7.3 | 26 | NO | NO |
CVE-2024-11289HIGH The Soledad theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 8.5.9 via several functions like penci_archive_more_post_ajax_func, penc | Dec 6, 2024 | 8.1 | 26 | NO | NO |
CVE-2025-68066HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion | Dec 16, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-59588HIGH Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion | Sep 22, 2025 | 7.5 | 25 | NO | NO |
CVE-2023-49825HIGH Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Th | Dec 20, 2023 | 8.1 | 23 | NO | NO |
CVE-2025-59589MEDIUM Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad soledad allows DOM-Based XSS.This issue affects Soledad: f | Sep 22, 2025 | 6.5 | 22 | NO | NO |
CVE-2022-3209MEDIUM The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site | Oct 10, 2022 | 6.1 | 22 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (17 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (17 CVEs).
Media Mentions
Signals from CVEs in this product scope (17 CVEs).
Top CNAs Publishing CVEs For Soledad
Top CWEs
Versions
No cataloged versions.