PT-2026-46213 · WordPress · Soliloquy Lite

·

CVE-2019-25743

·

Published

2026-06-04

·

Updated

2026-06-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Soliloquy Lite version 2.5.6
Description A persistent cross-site scripting issue allows authenticated attackers to inject malicious scripts by inserting script tags into the post title field. This is achieved by submitting POST requests to the post editing endpoint using the post title parameter. The injected scripts are stored and subsequently executed when users preview the post.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-25743

Affected Products

Soliloquy Lite