VYPR

Creta Testimonial Showcase

by WordPress

Source repositories

CVEs (1)

  • CVE-2025-10686HigNov 14, 2025
    risk 0.47cvss 7.2epss 0.00

    The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.