CVE-2026-96532
Description
AI Translation Available
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
https://wpscan.com/vulnerability/d1372d8a-6654-4da7-a07e-87b18a0b0db9/