CVE-2026-96532: Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update
Published Sep 26, 2026
·Updated
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.
Affected Software
1 affected component
Testimonials Widget<=4.0.4
Event History
Sep 26, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness
Frequently Asked Questions
1
Who can exploit this issue?
Unauthenticated users can exploit the vulnerable front-end testimonial submission form; no logged-in WordPress account is required.
2
What can an attacker change?
An attacker can create arbitrary posts or modify existing posts, including their title, content, and author.
3
Are existing posts at risk, or only newly submitted testimonials?
Existing posts are at risk because the issue permits overwriting the title, content, and author of any existing post.