CVE-2026-96533 Overview
CVE-2026-96533 is a Server-Side Request Forgery (SSRF) vulnerability in the Testimonials Widget WordPress plugin through version 4.0.4. The plugin fetches a user-supplied URL server-side without validation and stores the response as a public file. Unauthenticated attackers can abuse this behavior to make the server issue requests to internal services and read the returned content. The flaw is classified as [CWE-918] Server-Side Request Forgery.
Critical Impact
Unauthenticated remote attackers can pivot through the WordPress server to probe internal network services and exfiltrate response data stored as public files.
Affected Products
- Testimonials Widget WordPress plugin versions up to and including 4.0.4
- WordPress sites with the vulnerable plugin installed and active
- Hosting environments where the plugin can reach internal network resources
Discovery Timeline
- 2026-09-26 - CVE-2026-96533 published to NVD
- 2026-09-28 - Last updated in NVD database
Technical Details for CVE-2026-96533
Vulnerability Analysis
The Testimonials Widget plugin accepts a URL parameter from the client and performs a server-side HTTP request to retrieve its contents. The plugin then writes the response to a file accessible from the public web root. Because the request originates from the WordPress server, it can reach internal addresses and cloud metadata endpoints that are not exposed externally. The response payload becomes retrievable by any unauthenticated visitor through the stored file. This combination of unauthenticated access, server-initiated fetching, and public response storage distinguishes this flaw from blind SSRF variants.
Root Cause
The root cause is missing validation of the user-supplied URL before the plugin issues the outbound request. The plugin does not restrict scheme, host, or IP destination. There is no allow-list for permitted targets and no filter preventing requests to RFC1918 ranges, loopback addresses, or cloud metadata services such as 169.254.169.254. The absence of authentication checks on the endpoint compounds the risk.
Attack Vector
An unauthenticated attacker submits a crafted URL to the vulnerable plugin endpoint over the network. The WordPress server fetches the attacker-specified resource and writes the response to a predictable public location. The attacker then retrieves that file to read the response body. Typical targets include internal web services, administrative interfaces bound to localhost, Redis or Elasticsearch endpoints, and cloud instance metadata APIs that may expose temporary credentials.
See the WPScan Vulnerability Report for technical details.
Detection Methods for CVE-2026-96533
Indicators of Compromise
- Outbound HTTP requests from the WordPress server to internal IP ranges, loopback, or cloud metadata endpoints
- Unexpected files written to the plugin's public upload or cache directory containing non-testimonial content
- Access log entries showing unauthenticated POST or GET requests to Testimonials Widget plugin endpoints with URL parameters
Detection Strategies
- Inspect web server access logs for requests to plugin endpoints that include fully qualified URLs as parameter values
- Monitor egress traffic from WordPress hosts for connections to private address space or 169.254.169.254
- Review file creation events in the plugin's writable directories and flag files whose contents resemble HTTP responses from internal services
Monitoring Recommendations
- Enable WordPress audit logging for plugin activity and HTTP API calls initiated by wp_remote_get and related functions
- Forward web server, firewall, and egress proxy logs to a centralized analytics platform for correlation
- Alert on anomalous outbound DNS lookups from WordPress hosts referencing internal zone names or metadata hostnames
How to Mitigate CVE-2026-96533
Immediate Actions Required
- Deactivate the Testimonials Widget plugin until a patched release is confirmed by the maintainer
- Block outbound requests from WordPress hosts to RFC1918 ranges, loopback, and cloud metadata endpoints at the network layer
- Audit the plugin's public storage directory and remove any files containing responses from internal services
Patch Information
No fixed version has been published at the time of this writing. Monitor the WPScan Vulnerability Report and the plugin's official repository for an updated release addressing versions through 4.0.4.
Workarounds
- Enforce IMDSv2 on AWS instances to require session tokens for metadata access and reduce SSRF credential theft risk
- Place the WordPress server behind an egress proxy that enforces an allow-list of external destinations
- Use a web application firewall rule to block requests to the plugin endpoint containing URL-shaped parameter values
# Example egress restriction using iptables to block access to common SSRF targets
iptables -A OUTPUT -d 127.0.0.0/8 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 10.0.0.0/8 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 172.16.0.0/12 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 192.168.0.0/16 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 169.254.169.254 -m owner --uid-owner www-data -j REJECT
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.