PT-2025-50907 · WordPress · Pencidesign Soledad

Denver Jackson

·

Published

2025-12-12

·

Updated

2025-12-18

·

CVE-2025-64188

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PenciDesign Soledad versions n/a through 8.6.9
Description A flaw exists in PenciDesign Soledad that allows for privilege escalation. This allows subscribers to take over WordPress sites.
Recommendations Update PenciDesign Soledad to a version later than 8.6.9.

Fix

LPE

Incorrect Privilege Assignment

Weakness Enumeration

Related Identifiers

CVE-2025-64188

Affected Products

Pencidesign Soledad