CVE-2024-31368
- EPSS 0.44%
- Veröffentlicht 09.04.2024 09:15:25
- Zuletzt bearbeitet 28.04.2026 19:24:25
Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
CVE-2024-31367
- EPSS 0.43%
- Veröffentlicht 09.04.2024 09:15:25
- Zuletzt bearbeitet 28.04.2026 19:24:25
Missing Authorization vulnerability in PenciDesign Soledad.This issue affects Soledad: from n/a through 8.4.2.
CVE-2023-49826
- EPSS 0.57%
- Veröffentlicht 21.12.2023 13:15:09
- Zuletzt bearbeitet 28.04.2026 19:22:27
Deserialization of Untrusted Data vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme: from n/a through 8.4.1.
CVE-2023-49825
- EPSS 0.53%
- Veröffentlicht 20.12.2023 16:15:09
- Zuletzt bearbeitet 28.04.2026 19:22:27
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme.This issue affects Soledad – Multipurpose, Newspaper, Blog & WooCo...
CVE-2023-49827
- EPSS 0.39%
- Veröffentlicht 14.12.2023 15:15:09
- Zuletzt bearbeitet 28.04.2026 19:22:27
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Soledad – Multipurpose, Newspaper, Blog & WooCommerce WordPress Theme allows Reflected XSS.This issue affects Soledad – Multipurpose, Ne...
CVE-2022-41788
- EPSS 0.4%
- Veröffentlicht 18.11.2022 23:15:26
- Zuletzt bearbeitet 21.11.2024 07:23:50
Auth. (subscriber+) Cross-Site Scripting (XSS) vulnerability in Soledad premium theme <= 8.2.5 on WordPress.
CVE-2022-3209
- EPSS 0.49%
- Veröffentlicht 10.10.2022 21:15:11
- Zuletzt bearbeitet 21.11.2024 07:19:03
The soledad WordPress theme before 8.2.5 does not sanitise the {id,datafilter[type],...} parameters in its penci_more_slist_post_ajax AJAX action, leading to a Reflected Cross-Site Scripting (XSS) vulnerability.