VYPR
High severity7.2NVD Advisory· Published Nov 14, 2025· Updated Apr 15, 2026

CVE-2025-10686

CVE-2025-10686

Description

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Authenticated editors can leverage a Local File Inclusion bug in Creta Testimonial Showcase < 1.2.4 to include and execute arbitrary PHP files.

The Creta Testimonial Showcase WordPress plugin, before version 1.2.4, contains a Local File Inclusion (LFI) vulnerability. The root cause is improper sanitization of user-supplied file paths, allowing an attacker with editor-level access to include arbitrary files from the server's filesystem [1].

To exploit this vulnerability, an attacker must be authenticated with at least editor-level privileges within the WordPress site. No additional authentication is needed beyond the existing WordPress user session. The attacker can then craft a request that causes the plugin to include a remote or local file, such as a PHP shell, leading to code execution [1].

The impact is significant: an authenticated editor (or higher) can achieve arbitrary PHP code execution on the server. This can lead to full site compromise, data exfiltration, or further lateral movement within the hosting environment [1].

The vulnerability is patched in version 1.2.4 of the Creta Testimonial Showcase plugin. Users should update immediately to the latest version. The issue was publicly disclosed by researcher Khaled Alenazi (Nxploited) and published via WPScan on October 24, 2025 [1].

AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.