CVE-2026-96533
Received Received - Intake

Testimonials Widget WordPress Plugin Server-Side Request Forgery

Vulnerability report for CVE-2026-96533, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-26

Last updated on: 2026-09-26

Assigner: WPScan

Description

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-26
Last Modified
2026-09-26
Generated
2026-09-26
AI Q&A
2026-09-26
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpbeaverbuilder the_testimonials_widget to 4.0.4 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the Testimonials Widget WordPress plugin (version 4.0.4 or earlier). It allows unauthenticated users to trick the server into fetching a URL they specify. The server then stores the response as a public file without validating the URL. This can be used to make the server access internal services and read their responses, which is known as Server-Side Request Forgery (SSRF).

Detection Guidance

Check if the Testimonials Widget WordPress plugin version 4.0.4 or earlier is installed. Look for unusual server requests to internal services or public files created from user-supplied URLs. Review server logs for outbound requests to internal IP ranges or sensitive endpoints.

Impact Analysis

If you use this plugin, attackers could exploit it to access internal systems on your server or network. They might steal sensitive data, perform unauthorized actions, or disrupt services. Since the responses are stored publicly, others could also access the fetched data.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection. It may result in data breaches, unauthorized disclosures, and non-compliance with privacy regulations, potentially leading to legal penalties.

Mitigation Strategies

Disable or uninstall the Testimonials Widget WordPress plugin immediately. Restrict server access to internal services and monitor for unauthorized outbound requests. Apply network-level restrictions to block SSRF attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-96533. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart