CVE-2026-96532: Unknown Testimonials Widget

High severity, CVSS 7.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

Affected products

  • Unknown Testimonials Widget: up to and including 4.0.4

Published 2026-09-26. Last modified 2026-09-28.