---
id: CVE-2019-25743
title: WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site Scripting
summary: >-
  WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting
  vulnerability that allows authenticated attackers to inject malicious scripts
  by inserting script tags in the post title field. Attackers can submit POST
  requests …
severity: medium
cvss: 5.4
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-79
vendor: Soliloquywp
product: Soliloquy Lite
affected:
  - soliloquy_lite 2.5.6
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-06-04T14:02:52.233280Z'
exploitAvailable: true
published: '2026-06-04'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:23.490Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2019-25743'
references:
  - url: 'https://www.exploit-db.com/exploits/47517'
    label: ExploitDB-47517
  - url: 'https://soliloquywp.com/'
    label: Official Product Homepage
  - url: 'https://wordpress.org/plugins/soliloquy-lite/'
    label: Product Reference
  - url: >-
      https://www.vulncheck.com/advisories/wordpress-soliloquy-lite-persistent-cross-site-scripting
    label: >-
      VulnCheck Advisory: WordPress Soliloquy Lite 2.5.6 Persistent Cross-Site
      Scripting
tags:
  - cve.org
  - exploit-available
epss: 0.00171
epssPercentile: 0.05834
ingestedAt: '2026-10-01T15:48:17.883Z'
---

## Overview

WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the post_title parameter, which are stored and executed when users preview the post.

## Affected

- `soliloquy_lite 2.5.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
