CVE-2026-96532: Unknown Testimonials Widget
High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
Affected products
- Unknown Testimonials Widget: up to and including 4.0.4
Published 2026-09-26. Last modified 2026-09-28.