Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 26 Sep 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-284 CWE-862 |
Sat, 26 Sep 2026 06:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post. | |
| Title | Testimonials Widget <= 4.0.4 - Unauthenticated Arbitrary Post Update | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-26T22:41:13.804Z
Reserved: 2026-09-23T11:24:56.363Z
Link: CVE-2026-96532
No data.
Status : Received
Published: 2026-09-26T07:17:03.527
Modified: 2026-09-26T07:17:03.527
Link: CVE-2026-96532
No data.
OpenCVE Enrichment
Updated: 2026-09-26T07:45:06Z