CVE-2025-32657: WordPress Testimonial Slider and Showcase Pro plugin <= 2.1.7 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in RadiusTheme Testimonial Slider And Showcase Pro testimonial-slider-showcase-pro allows PHP Local File Inclusion.This issue affects Testimonial Slider And Showcase Pro: from n/a through <= 2.1.7.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32657?
CVE-2025-32657 has a high severity due to its potential for remote file inclusion and local file inclusion attacks.
How do I fix CVE-2025-32657?
To fix CVE-2025-32657, update the RadiusTheme Testimonial Slider And Showcase Pro plugin to version 2.1.8 or later.
What systems are affected by CVE-2025-32657?
CVE-2025-32657 affects RadiusTheme Testimonial Slider And Showcase Pro and WordPress Testimonial Slider and Showcase Pro versions up to and including 2.1.7.
What types of attacks can CVE-2025-32657 facilitate?
CVE-2025-32657 can facilitate remote file inclusion and local file inclusion attacks.
Is CVE-2025-32657 a common vulnerability?
While not extremely common, CVE-2025-32657 is significant and can pose real risks to websites using the affected software.