CVE-2025-68996: WordPress Responsive Posts Carousel Pro plugin <= 15.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in WebCodingPlace Responsive Posts Carousel Pro responsive-posts-carousel-pro allows PHP Local File Inclusion.This issue affects Responsive Posts Carousel Pro: from n/a through <= 15.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68996?
CVE-2025-68996 is classified as a high severity vulnerability due to the potential for remote file inclusion.
How do I fix CVE-2025-68996?
To fix CVE-2025-68996, update the Responsive Posts Carousel Pro plugin to the latest version beyond 15.1.
What type of vulnerability is CVE-2025-68996?
CVE-2025-68996 is an improper control of filename for include/require statement vulnerability leading to PHP Local File Inclusion.
What software is affected by CVE-2025-68996?
CVE-2025-68996 affects Responsive Posts Carousel Pro versions up to and including 15.1.
What can attackers achieve with CVE-2025-68996?
Attackers can potentially exploit CVE-2025-68996 to execute arbitrary code by including malicious files.