
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68996 is a Local File Inclusion (LFI) vulnerability in the Responsive Posts Carousel Pro WordPress plugin by WebCodingPlace, affecting all versions up to and including 15.1. The flaw is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program) and was discovered by researcher Phat RiO, reported on November 25, 2025, and published on December 25–30, 2025. No official patch was available at the time of disclosure. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The vulnerability stems from improper control of filenames used in PHP include/require statements within the Responsive Posts Carousel Pro plugin (CWE-98), enabling PHP Local File Inclusion. An authenticated attacker with at least Contributor-level privileges can supply a crafted filename parameter that causes the plugin to include arbitrary local files from the server's filesystem. The attack vector is network-based with high attack complexity and requires low privileges but no user interaction (Patchstack). No public proof-of-concept code has been identified at this time.
Successful exploitation allows an attacker to read arbitrary local files on the web server, including sensitive configuration files such as wp-config.php, which contains database credentials. This could lead to full database compromise, credential theft, and potentially further lateral movement within the hosting environment. Confidentiality, integrity, and availability are all rated as high impact per the CVSS scoring (Patchstack).
The vulnerability requires an authenticated attacker with at least Contributor-level WordPress privileges, which limits opportunistic mass exploitation but does not eliminate risk on sites with open registration or multiple contributors. The EPSS score is approximately 0.086%, indicating a low but non-zero probability of exploitation in the near term. No in-the-wild exploitation, threat actor attribution, or CISA KEV catalog listing has been reported as of the time of this report. Patchstack classifies the priority as Low, noting it is unlikely to be exploited at scale (Patchstack).
../../../../wp-config.php) in the vulnerable filename parameter to trigger local file inclusion.wp-config.php), which the attacker can use for further compromise such as database access or privilege escalation (Patchstack).../, ..%2F, or encoded variants) in filename parameters.include()/require() failures for files outside the plugin directory.wp-config.php, .env, or system files like /etc/passwd.At the time of disclosure, no official patch was available for Responsive Posts Carousel Pro. Site administrators should immediately deactivate and remove the plugin until a patched version is released by WebCodingPlace. As a compensating control, restrict WordPress user registration and limit Contributor-level accounts to trusted users only. Deploying a Web Application Firewall (WAF) with rules targeting path traversal and LFI patterns can provide additional protection. Patchstack users with virtual patching enabled receive automatic mitigation (Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, indicating routine tracking by the WordPress security community (Wordfence). Brief mentions appeared on security-focused social media accounts including TheHackerWire on Infosec.Exchange and Bluesky, though no significant community debate or vendor response has been noted. Overall industry reaction has been minimal, consistent with Patchstack's low-priority classification.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."