OFFLINE
Awaiting data
Security intelligence
MinorCritical vulnerability

CVE-2026-96532 (CVSS 7.5)

NVD · officialPublished Sep 26, 2026Risk 23/100EPSS 0.1%

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

CVSS
7.5
AV:NetworkAC:LowPR:NoneUI:NoneC:NoneI:HighA:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source