CVE-2026-96533
Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.
| Vendor | unknown |
| Product | testimonials widget |
| Published | Sep 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown testimonials widget
Be the first to know when new unknown vulnerabilities affecting unknown testimonials widget are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Testimonials Widget
0 โค 4.0.4
References
Credits
Naiches WPScan