CVE-2026-96532 PUBLISHED

Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update

Assigner: WPScan
Reserved: 23.09.2026 Published: 26.09.2026 Updated: 26.09.2026

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

Product Status

Vendor Unknown
Product Testimonials Widget
Versions Default: unknown
  • affected from 0 to 4.0.4 (incl.)

Credits

  • Naiches finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE