CVE-2026-96532
EUVD-2026-8754026.09.2026, 07:17
The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.