DOM-Based XSS Vulnerability in PenciDesign Soledad Theme
CVE-2025-59589

6.5MEDIUM

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
22 September 2025

What is CVE-2025-59589?

A DOM-Based Cross-site Scripting (XSS) vulnerability exists in the PenciDesign Soledad theme, affecting versions from n/a through 8.6.8. This issue arises from improper handling of user input during web page generation, leading to potential exploitation by attackers. Users of the affected versions should promptly update their theme to mitigate the risk of malicious scripts being executed in users' browsers.

Affected Version(s)

Soledad <= 8.6.8

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) (Patchstack Alliance)
.
CVE-2025-59589 : DOM-Based XSS Vulnerability in PenciDesign Soledad Theme