The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Fri, 14 Nov 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. | |
| Title | Creta Testimonial Showcase < 1.2.4 - Editor+ Local File Inclusion | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-11-14T06:00:09.051Z
Reserved: 2025-09-18T12:57:28.356Z
Link: CVE-2025-10686
No data.
Status : Received
Published: 2025-11-14T06:15:42.567
Modified: 2025-11-14T06:15:42.567
Link: CVE-2025-10686
No data.
OpenCVE Enrichment
No data.