---
id: CVE-2025-10686
title: >-
  The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to
  Local File Inclusion
summary: >-
  The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to
  Local File Inclusion. This makes it possible for authenticated attackers, with
  editor-level access and above, to include and execute arbitrary files on the
  ser…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
published: '2025-11-14'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10686'
references:
  - url: 'https://wpscan.com/vulnerability/27d58c5a-ab87-41aa-a806-53fa96d4351c/'
    label: contact@wpscan.com
tags:
  - nvd
epss: 0.00486
epssPercentile: 0.39864
ingestedAt: '2026-10-07T21:54:15.037Z'
---

## Overview

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
