DOM-Based XSS Vulnerability in PenciDesign Soledad Theme
CVE-2025-59589
6.5MEDIUM
What is CVE-2025-59589?
A DOM-Based Cross-site Scripting (XSS) vulnerability exists in the PenciDesign Soledad theme, affecting versions from n/a through 8.6.8. This issue arises from improper handling of user input during web page generation, leading to potential exploitation by attackers. Users of the affected versions should promptly update their theme to mitigate the risk of malicious scripts being executed in users' browsers.
Affected Version(s)
Soledad <= 8.6.8
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
João Pedro S Alcântara (Kinorth) (Patchstack Alliance)