---
id: CVE-2026-96532
title: >-
  The Testimonials Widget WordPress plugin through 4.0.4 does not perform a
  capability or ownership check when handling its front-end testimonial
  submission form, allowing unauthenticated users to modify or create arbitrary
  posts, includin…
summary: >-
  The Testimonials Widget WordPress plugin through 4.0.4 does not perform a
  capability or ownership check when handling its front-end testimonial
  submission form, allowing unauthenticated users to modify or create arbitrary
  posts, includin…
severity: none
cwe:
  - CWE-862
product: Testimonials Widget
affected:
  - testimonials_widget <= 4.0.4
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T07:17:03.527'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96532'
references:
  - url: 'https://wpscan.com/vulnerability/d1372d8a-6654-4da7-a07e-87b18a0b0db9/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T06:27:03.680Z'
---

## Overview

The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
