๐Ÿ” CVE Alert

CVE-2026-96532

UNKNOWN 0.0

Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

Vendor unknown
Product testimonials widget
Published Sep 26, 2026
Stay Ahead of the Next One

Get instant alerts for unknown testimonials widget

Be the first to know when new unknown vulnerabilities affecting unknown testimonials widget are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Testimonials Widget
0 โ‰ค 4.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/d1372d8a-6654-4da7-a07e-87b18a0b0db9/

Credits

Naiches WPScan