CVE-2026-96533

Published: Set 26, 2026 Last Modified: Set 26, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.

https://wpscan.com/vulnerability/062284b2-b55d-42e2-8dda-ced7845d7df0/