CVE-2025-10686high

CVE-2025-10686: high-severity vulnerability in Creta Testimonial Showcase

Creta Testimonial Showcase < 1.2.4 - Editor+ Local File Inclusion

Published

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.2epss 0.5%
exploitation probability
0.5%top 60% of all CVEs
observed exploitation
nono source reports it
The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H