CVE-2026-96532

Published: Set 26, 2026 Last Modified: Set 26, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

https://wpscan.com/vulnerability/d1372d8a-6654-4da7-a07e-87b18a0b0db9/