CVE-2025-32656: WordPress Testimonial Slider and Showcase Pro plugin <= 2.3.15 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in NotFound Testimonial Slider And Showcase Pro allows PHP Local File Inclusion. This issue affects Testimonial Slider And Showcase Pro: from n/a through 2.3.15.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.3.15.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32656?
The severity of CVE-2025-32656 is rated high with a CVSS score of 8.1.
How do I fix CVE-2025-32656?
To fix CVE-2025-32656, upgrade to a version of the WordPress Testimonial Slider And Showcase Pro plugin that is greater than 2.3.15.
What type of vulnerability is CVE-2025-32656?
CVE-2025-32656 is a Local File Inclusion vulnerability caused by improper control of filename for include statements in PHP.
What versions are affected by CVE-2025-32656?
CVE-2025-32656 affects the WordPress Testimonial Slider And Showcase Pro plugin from any version up to and including 2.3.15.
Can CVE-2025-32656 lead to remote code execution?
While primarily a Local File Inclusion vulnerability, CVE-2025-32656 may potentially allow attackers to execute arbitrary code if exploited successfully.