{"id":"CVE-2026-96533","published":"2026-09-26T07:17:03.630","lastModified":"2026-09-28T15:17:09.083","description":"The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.","cvssScore":5.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N","cwes":["CWE-918"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/062284b2-b55d-42e2-8dda-ced7845d7df0/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}