CVE-2026-96533 - Testimonials Widget <= 4.0.4 - Unauthenticated SSRF via Featured Image URL
CVE ID :CVE-2026-96533
Published : Sept. 26, 2026, 6 a.m. | 1 hour, 11 minutes ago
Description :The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 26, 2026, 6 a.m. | 1 hour, 11 minutes ago
Description :The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...