---
id: CVE-2026-96533
title: >-
  The Testimonials Widget WordPress plugin through 4.0.4 does not validate a
  user-supplied URL before fetching it server-side and storing the response as a
  public file, allowing unauthenticated users to make the server issue requests
  to in…
summary: >-
  The Testimonials Widget WordPress plugin through 4.0.4 does not validate a
  user-supplied URL before fetching it server-side and storing the response as a
  public file, allowing unauthenticated users to make the server issue requests
  to in…
severity: none
cwe:
  - CWE-918
product: Testimonials Widget
affected:
  - testimonials_widget <= 4.0.4
published: '2026-09-26'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T07:17:03.630'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-96533'
references:
  - url: 'https://wpscan.com/vulnerability/062284b2-b55d-42e2-8dda-ced7845d7df0/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-26T06:27:03.678Z'
---

## Overview

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
