CVE-2026-96532 UNKNOWN

CVE-2026-96532

Published: 2026-09-26

Description

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…