CVE-2025-59588

WordPress Soledad Theme <= 8.6.8 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad allows PHP Local File Inclusion. This issue affects Soledad: from n/a through 8.6.8.


We have discovered 13,305 live websites that are affected by CVE-2025-59588.

Run a Free Instant Scan




Affected Software

Product  Soledad
Category Wordpress Themes
Vulnerable Domains13,305 live websites (91% of Soledad install base)
Vulnerable Versions
  • from 0 through 8.6.8
Vulnerable Versions Count137 versions ( 98% of all versions)


Common Weakness Enumeration

CWE-98 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')



Details

  • Published - Sep 22, 2025
  • Updated - Sep 23, 2025

Credits

  • João Pedro S Alcântara (Kinorth) (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-59588
United States4,164 websites



France2,045 websites
Germany891 websites
Poland667 websites
GB593 websites
Italy413 websites
Russia380 websites
Netherlands317 websites
Cyprus309 websites
Brazil294 websites

Website Distribution by TLD

Number of websites using CVE-2025-59588
.com6,515 websites
.net671 websites
.org604 websites
.pl542 websites
.fr465 websites
.de365 websites
.ru333 websites
.it326 websites
.nl297 websites
.com.br261 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-59588

Top websites that are affected by CVE-2025-59588. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
**********.cz Czech Republic*,***
**.ua Ukraine**,***
*****************.be Belgium**,***
**************.cz Czech Republic**,***
******.be Belgium**,***
*****.es Spain**,***
***.***.tr Turkey**,***
************.cz Czech Republic**,***
**********.com United States**,***
*******.com United States**,***
See full domain list

FAQ

CVE-2025-59588 is Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') in Soledad
A total of 13,305 websites have been identified as vulnerable to CVE-2025-59588, based on global website indexing conducted by WebTechSurvey.
The Soledad is affected by the CVE-2025-59588 vulnerability.
Soledad versions up to and including 8.6.8 are vulnerable to CVE-2025-59588.