Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-69j2-g6ff-ww92

Опубликовано: 14 нояб. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 7.2

Описание

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

EPSS

Процентиль: 28%
0.00099
Низкий

7.2 High

CVSS3

Связанные уязвимости

CVSS3: 7.2
nvd
3 месяца назад

The Creta Testimonial Showcase WordPress plugin before 1.2.4 is vulnerable to Local File Inclusion. This makes it possible for authenticated attackers, with editor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files.

EPSS

Процентиль: 28%
0.00099
Низкий

7.2 High

CVSS3