Executive brief
Soledad is a popular premium theme for WordPress websites. A security flaw in the theme allows logged-in users with low-level permissions, such as subscribers, to access features or perform actions that should be restricted to administrators. This could lead to unauthorized changes to the website's configuration or the exposure of sensitive internal information.
Technical details
A missing authorization vulnerability (CWE-862) exists in the Soledad theme for WordPress through version 8.2.5. The software fails to properly enforce access control lists (ACLs) on certain functions, allowing an authenticated attacker with 'Subscriber' level privileges to execute actions intended for higher-privileged roles. The attack is reachable over the network and does not require user interaction. The issue is resolved in version 8.2.6.
Affected products
- TemplateHouse Soledad <= 8.2.5
Timeline
- 2022-11-01: disclosed: Vulnerability reported by Patchstack researcher
- 2022-11-01: patched: Version 8.2.6 released to address the issue
- 2026-06-11: advisory: NVD publication date