WordPress · Testimonials Widget · CVE-2026-96532
**Name of the Vulnerable Software and Affected Versions**
The Testimonials Widget WordPress plugin versions prior to 4.0.5
**Description**
The plugin fails to perform capability or ownership checks when processing the front-end testimonial submission form. This allows unauthenticated users to create arbitrary posts or modify existing ones, including the ability to overwrite the title, content, and author.
**Recommendations**
Update the plugin to version 4.0.5 or later.