Vulnerabilidades en pencidesign

33 resultados
CVE-2024-3551CRITICALPenci Soledad Data Migrator <= 1.3.0 - Unauthenticated Local File InclusionEPSS 0.7%CVE-2024-11289HIGHSoledad <= 8.5.9 - Unauthenticated Limited Local File InclusionEPSS 0.7%CVE-2023-49826HIGHWordPress Soledad Theme <= 8.4.1 is vulnerable to PHP Object InjectionEPSS 0.6%CVE-2023-49825HIGHWordPress Soledad Theme <= 8.4.1 is vulnerable to SQL InjectionEPSS 0.5%CVE-2025-8142HIGHSoledad <= 8.6.7 - Authenticated (Contributor+) Local File Inclusion via 'header_layout'EPSS 0.5%CVE-2024-31368MEDIUMWordPress Soledad theme <= 8.4.2 - Unauthenticated Broken Access Control vulnerabilityEPSS 0.4%CVE-2024-31367HIGHWordPress Soledad theme <= 8.4.2 - Authenticated Broken Access Control vulnerabilityEPSS 0.4%CVE-2025-64223HIGHWordPress PenNews theme < 6.7.3 - Local File Inclusion vulnerabilityEPSS 0.4%CVE-2022-41788MEDIUMWordPress Soledad premium theme <= 8.2.5 - Auth. Cross-Site Scripting (XSS) vulnerabilityEPSS 0.4%CVE-2023-49827HIGHWordPress Soledad Theme <= 8.4.1 is vulnerable to Cross Site Scripting (XSS)EPSS 0.4%CVE-2025-59588HIGHWordPress Soledad Theme <= 8.6.8 - Local File Inclusion VulnerabilityEPSS 0.4%CVE-2025-64188CRITICALWordPress Soledad theme <= 8.6.9 - Privilege Escalation vulnerabilityEPSS 0.4%CVE-2025-68066HIGHWordPress Soledad theme <= 8.7.0 - Local File Inclusion vulnerabilityEPSS 0.3%CVE-2025-8105HIGHSoledad <= 8.6.7 - Unauthenticated Arbitrary Shortcode ExecutionEPSS 0.3%CVE-2024-31369MEDIUMWordPress Soledad theme <= 8.4.2 - Cross Site Request Forgery (CSRF) vulnerabilityEPSS 0.2%CVE-2025-67572MEDIUMWordPress PenNews theme < 6.7.4 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-27055MEDIUMWordPress Penci AI SmartContent Creator plugin <= 2.0 - Broken Access Control vulnerabilityEPSS 0.2%CVE-2026-24600MEDIUMWordPress Penci Review plugin <= 3.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2026-24601MEDIUMWordPress Penci Pay Writer plugin <= 1.5 - Cross Site Scripting (XSS) vulnerabilityEPSS 0.2%CVE-2025-8143MEDIUMSoledad <= 8.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'pcsml_smartlists_h'EPSS 0.2%