Unrated severityNVD Advisory· Published Sep 26, 2026
CVE-2026-96533
CVE-2026-96533
Description
The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2<=4.0.4+ 1 more
- (no CPE)range: <=4.0.4
- (no CPE)range: <=4.0.4
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.