Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

soledad — Vulnerabilities & Security Advisories 14

All 14 CVE vulnerabilities found in soledad, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses associated with the Soledad software product, categorized under the Common Weakness Enumeration (CWE) framework. It serves as a central repository for tracking reported vulnerabilities, providing detailed insights into the specific flaws that affect this encryption and communication tool. The collection includes a comprehensive range of vulnerability types, such as memory corruption issues, cryptographic implementation errors, and privilege escalation flaws. The data spans from the initial release of the software through recent updates, ensuring that historical context is preserved alongside current threat intelligence. By aggregating reports from various sources, this page offers a chronological view of how security issues have evolved within the Soledad ecosystem over time. Users can utilize this resource to monitor vendor advisories and understand the broader implications of specific weakness classes on the product's architecture. It allows for a deeper look into the product’s vulnerability history, helping administrators and developers identify patterns in past incidents. This information supports risk assessment and informs decisions regarding patching priorities and security configurations. The goal is to provide transparency and actionable data for anyone relying on or contributing to the Soledad project, facilitating better defense strategies against emerging threats.

Vendor: Unknown

CVE ID Title CVSS Severity Published
CVE-2022-42479 WordPress Soledad premium theme <= 8.2.5 - Broken Access Control vulnerability CWE-862 5.4 Medium 2026-06-11
CVE-2026-27069 WordPress Soledad theme <= 8.7.2 - Cross Site Scripting (XSS) vulnerability CWE-79 6.5 Medium 2026-02-19
CVE-2025-64188 WordPress Soledad theme <= 8.6.9 - Privilege Escalation vulnerability CWE-266 9.8 Critical 2025-12-18
CVE-2025-68066 WordPress Soledad theme <= 8.7.0 - Local File Inclusion vulnerability CWE-98 7.5 High 2025-12-16
CVE-2025-59588 WordPress Soledad Theme <= 8.6.8 - Local File Inclusion Vulnerability CWE-98 7.5 High 2025-09-22
CVE-2025-59589 WordPress Soledad Theme <= 8.6.8 - Cross Site Scripting (XSS) Vulnerability CWE-79 6.5 Medium 2025-09-22
CVE-2025-8143 Soledad <= 8.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h' CWE-79 6.4 Medium 2025-08-16
CVE-2025-8105 Soledad <= 8.6.7 - Unauthenticated Arbitrary Shortcode Execution CWE-94 7.3 High 2025-08-16
CVE-2025-8142 Soledad <= 8.6.7 - Authenticated (Contributor+) Local File Inclusion via 'header_layout' CWE-98 8.8 High 2025-08-16
CVE-2024-11289 Soledad <= 8.5.9 - Unauthenticated Limited Local File Inclusion CWE-98 8.1 High 2024-12-06
CVE-2024-31369 WordPress Soledad theme <= 8.4.2 - Cross Site Request Forgery (CSRF) vulnerability CWE-352 5.4 Medium 2024-04-09
CVE-2024-31368 WordPress Soledad theme <= 8.4.2 - Unauthenticated Broken Access Control vulnerability CWE-862 6.5 Medium 2024-04-09
CVE-2024-31367 WordPress Soledad theme <= 8.4.2 - Authenticated Broken Access Control vulnerability CWE-862 7.1 High 2024-04-09
CVE-2022-3209 Soledad < 8.2.5 - Reflected Cross-site Scripting CWE-79 6.1 - 2022-10-10

All 14 known CVE vulnerabilities affecting soledad with full Chinese analysis, references, and POCs where available.