OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-96532

HIGH · CVSS 7.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

The Testimonials Widget plugin for WordPress versions up to 4.0.4 is vulnerable due to a lack of capability or ownership checks in its front-end testimonial submission form, enabling unauthenticated users to create or modify posts. This can lead to unauthorized changes to existing content, including overwriting titles, content, and authorship of posts. WordPress site administrators using this plugin should prioritize updating to mitigate potential content manipulation risks.

CVE
CVE-2026-96532
Severity
HIGH
CVSS
7.5
EPSS
0.21%
WordPress

Original NVD Description

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.