CVE-2026-96532
Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
| Vendor | unknown |
| Product | testimonials widget |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown testimonials widget
Be the first to know when new unknown vulnerabilities affecting unknown testimonials widget are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Testimonials Widget
0 โค 4.0.4
References
Credits
Naiches WPScan