{"id":"CVE-2026-96532","published":"2026-09-26T07:17:03.527","lastModified":"2026-09-28T15:17:09.083","description":"The Testimonials Widget WordPress plugin through 4.0.4 does not perform a capability or ownership check when handling its front-end testimonial submission form, allowing unauthenticated users to modify or create arbitrary posts, including overwriting the title, content and author of any existing post.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/d1372d8a-6654-4da7-a07e-87b18a0b0db9/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}