Skip to main content
Vulnerability Database/CVE-2026-96533

CVE-2026-96533: Testimonials Widget WordPress SSRF Flaw

CVE-2026-96533 is a server-side request forgery vulnerability in the Testimonials Widget WordPress plugin that lets attackers access internal services. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-96533 Overview

CVE-2026-96533 is a Server-Side Request Forgery (SSRF) vulnerability in the Testimonials Widget WordPress plugin through version 4.0.4. The plugin fetches a user-supplied URL server-side without validation and stores the response as a public file. Unauthenticated attackers can abuse this behavior to make the server issue requests to internal services and read the returned content. The flaw is classified as [CWE-918] Server-Side Request Forgery.

Critical Impact

Unauthenticated remote attackers can pivot through the WordPress server to probe internal network services and exfiltrate response data stored as public files.

Affected Products

  • Testimonials Widget WordPress plugin versions up to and including 4.0.4
  • WordPress sites with the vulnerable plugin installed and active
  • Hosting environments where the plugin can reach internal network resources

Discovery Timeline

  • 2026-09-26 - CVE-2026-96533 published to NVD
  • 2026-09-28 - Last updated in NVD database

Technical Details for CVE-2026-96533

Vulnerability Analysis

The Testimonials Widget plugin accepts a URL parameter from the client and performs a server-side HTTP request to retrieve its contents. The plugin then writes the response to a file accessible from the public web root. Because the request originates from the WordPress server, it can reach internal addresses and cloud metadata endpoints that are not exposed externally. The response payload becomes retrievable by any unauthenticated visitor through the stored file. This combination of unauthenticated access, server-initiated fetching, and public response storage distinguishes this flaw from blind SSRF variants.

Root Cause

The root cause is missing validation of the user-supplied URL before the plugin issues the outbound request. The plugin does not restrict scheme, host, or IP destination. There is no allow-list for permitted targets and no filter preventing requests to RFC1918 ranges, loopback addresses, or cloud metadata services such as 169.254.169.254. The absence of authentication checks on the endpoint compounds the risk.

Attack Vector

An unauthenticated attacker submits a crafted URL to the vulnerable plugin endpoint over the network. The WordPress server fetches the attacker-specified resource and writes the response to a predictable public location. The attacker then retrieves that file to read the response body. Typical targets include internal web services, administrative interfaces bound to localhost, Redis or Elasticsearch endpoints, and cloud instance metadata APIs that may expose temporary credentials.

See the WPScan Vulnerability Report for technical details.

Detection Methods for CVE-2026-96533

Indicators of Compromise

  • Outbound HTTP requests from the WordPress server to internal IP ranges, loopback, or cloud metadata endpoints
  • Unexpected files written to the plugin's public upload or cache directory containing non-testimonial content
  • Access log entries showing unauthenticated POST or GET requests to Testimonials Widget plugin endpoints with URL parameters

Detection Strategies

  • Inspect web server access logs for requests to plugin endpoints that include fully qualified URLs as parameter values
  • Monitor egress traffic from WordPress hosts for connections to private address space or 169.254.169.254
  • Review file creation events in the plugin's writable directories and flag files whose contents resemble HTTP responses from internal services

Monitoring Recommendations

  • Enable WordPress audit logging for plugin activity and HTTP API calls initiated by wp_remote_get and related functions
  • Forward web server, firewall, and egress proxy logs to a centralized analytics platform for correlation
  • Alert on anomalous outbound DNS lookups from WordPress hosts referencing internal zone names or metadata hostnames

How to Mitigate CVE-2026-96533

Immediate Actions Required

  • Deactivate the Testimonials Widget plugin until a patched release is confirmed by the maintainer
  • Block outbound requests from WordPress hosts to RFC1918 ranges, loopback, and cloud metadata endpoints at the network layer
  • Audit the plugin's public storage directory and remove any files containing responses from internal services

Patch Information

No fixed version has been published at the time of this writing. Monitor the WPScan Vulnerability Report and the plugin's official repository for an updated release addressing versions through 4.0.4.

Workarounds

  • Enforce IMDSv2 on AWS instances to require session tokens for metadata access and reduce SSRF credential theft risk
  • Place the WordPress server behind an egress proxy that enforces an allow-list of external destinations
  • Use a web application firewall rule to block requests to the plugin endpoint containing URL-shaped parameter values
bash
# Example egress restriction using iptables to block access to common SSRF targets
iptables -A OUTPUT -d 127.0.0.0/8 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 10.0.0.0/8 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 172.16.0.0/12 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 192.168.0.0/16 -m owner --uid-owner www-data -j REJECT
iptables -A OUTPUT -d 169.254.169.254 -m owner --uid-owner www-data -j REJECT

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.