CVE-2015-10147
WordPress vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2015-10147) affects the Easy Testimonial Slider and Form WordPress plugin versions 1.0.2 and below. It is an authenticated SQL injection vulnerability that requires administrator or higher privileges to exploit. The vulnerability was discovered by Ala Arfaoui and was publicly disclosed on October 28, 2025 (Wordfence Threat Intel).

Technical details

This is an authenticated SQL injection vulnerability with a CVSS score of 4.9 (Medium severity). The vulnerability requires administrator or higher level privileges to exploit, indicating it is only exploitable by trusted users with significant access to the system (Wordfence Threat Intel).

Impact

Given that this vulnerability requires administrator privileges to exploit, the potential impact is somewhat limited since it can only be exploited by users who already have significant access to the system. However, successful exploitation could potentially allow an authenticated administrator to perform unauthorized database operations (Wordfence Threat Intel).

Mitigation and workarounds

Users should upgrade the Easy Testimonial Slider and Form plugin to a version higher than 1.0.2 to remediate this vulnerability. Additionally, following security best practices such as limiting administrator access and regularly reviewing admin accounts is recommended (WordPress Plugin Directory).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-9544MEDIUM6.5
  • doppler-form
NoYesOct 29, 2025
CVE-2015-10147MEDIUM4.9
  • easy-testimonial-rotator
NoYesOct 29, 2025
CVE-2015-10146MEDIUM4.9
  • wp-responsive-slider-with-lightbox
NoYesOct 29, 2025
CVE-2025-11632MEDIUM4.3
  • call-now-button
NoYesOct 29, 2025
CVE-2025-11587MEDIUM4.3
  • call-now-button
NoYesOct 29, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management