Retour à la veille

CVE-2026-96533

Publié : 26 septembre 2026
Modifié : 26 septembre 2026
Lien officiel NVD

Description détaillée

The Testimonials Widget WordPress plugin through 4.0.4 does not validate a user-supplied URL before fetching it server-side and storing the response as a public file, allowing unauthenticated users to make the server issue requests to internal services and read the responses.

Références et Patchs