CVE-2025-64188: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64188 is a critical Incorrect Privilege Assignment vulnerability in the PenciDesign Soledad WordPress theme that allows privilege escalation. It affects all versions of Soledad up to and including 8.6.9, with the patched version being 8.6.9.1. The vulnerability was reported by security researcher Denver Jackson on September 23, 2025, and published by Patchstack on October 23, 2025; it was formally assigned a CVE and published to NVD on December 18, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) (Patchstack).

Technical details

The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment) and maps to OWASP Top 10 category A1: Broken Access Control. A user with only Subscriber-level privileges can exploit this flaw to escalate their account to a higher privilege role within the WordPress installation. The attack is network-based, requires no user interaction, and has low attack complexity, meaning any authenticated subscriber on the affected site can trigger the escalation without special conditions (Patchstack). No public proof-of-concept code has been disclosed as of the time of reporting.

Impact

Successful exploitation allows a low-privileged subscriber account to gain elevated — potentially administrator-level — privileges on the WordPress site, resulting in full confidentiality, integrity, and availability compromise. An attacker with administrative access could install malicious plugins, exfiltrate sensitive data, deface the site, create backdoor accounts, or pivot to the underlying server infrastructure. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of websites simultaneously, regardless of site size or traffic (Patchstack).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.017% (0.000170), indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies this as high priority and warns it is the type of vulnerability expected to be used in mass-exploit campaigns (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Soledad theme version 8.6.9 or earlier using tools like WPScan, Shodan, or by inspecting theme metadata in page source (/wp-content/themes/soledad/style.css).
  2. Account Registration: Register or obtain a low-privileged Subscriber account on the target WordPress site (if open registration is enabled, this requires no prior access).
  3. Privilege Escalation: Leverage the incorrect privilege assignment flaw in the Soledad theme to submit a crafted request that assigns elevated roles (e.g., Administrator) to the attacker's account, bypassing proper access controls.
  4. Full Site Takeover: With administrator privileges, log into the WordPress dashboard to install malicious plugins, create backdoor accounts, exfiltrate data, or modify site content (Patchstack).

Indicators of compromise

  • Logs: WordPress authentication logs showing a Subscriber-role user account suddenly performing administrator-level actions; unexpected role changes in wp_usermeta database table (e.g., wp_capabilities field updated to administrator).
  • File System: New or modified plugin files in /wp-content/plugins/; presence of web shells or unfamiliar PHP files in the WordPress directory tree; unexpected changes to wp-config.php.
  • Network: Unusual POST requests to WordPress admin endpoints (e.g., /wp-admin/user-edit.php, /wp-admin/admin-ajax.php) originating from low-privileged user sessions.
  • Process: Unexpected outbound connections from the web server process; new cron jobs or scheduled tasks added via WordPress (wp_cron) by non-administrative users.

Mitigation and workarounds

The vendor has released a patched version: update the Soledad WordPress theme to version 8.6.9.1 or later immediately. Patchstack has also issued a virtual patching/mitigation rule for subscribers of its service to block exploitation attempts until the theme is updated. As additional hardening measures, disable open user registration if not required, audit existing user roles for unexpected privilege assignments, and enforce the principle of least privilege across all WordPress user accounts (Patchstack).

Community reactions

Security Online Info covered the vulnerability with a headline emphasizing that the flaw allows subscribers to take over WordPress sites, highlighting the severity for site owners. The vulnerability was also discussed on Bluesky within the infosec community shortly after disclosure. Patchstack, which discovered and coordinated the disclosure, characterized it as a high-priority issue likely to be targeted in mass-exploit campaigns (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management