The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.
Metrics
Affected Vendors & Products
References
History
Sat, 15 Nov 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress |
|
| Vendors & Products |
Wordpress
Wordpress wordpress |
Fri, 14 Nov 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Fri, 14 Nov 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. | |
| Title | Creta Testimonial Showcase < 1.2.4 - Editor+ Local File Inclusion | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-11-14T15:08:08.868Z
Reserved: 2025-09-18T12:57:28.356Z
Link: CVE-2025-10686
Updated: 2025-11-14T14:53:37.823Z
Status : Awaiting Analysis
Published: 2025-11-14T06:15:42.567
Modified: 2025-11-14T16:42:03.187
Link: CVE-2025-10686
No data.