The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.
History

Thu, 13 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Lingotek-translation
Lingotek-translation ray Enterprise Translation
Wordpress
Wordpress wordpress
Vendors & Products Lingotek-translation
Lingotek-translation ray Enterprise Translation
Wordpress
Wordpress wordpress

Tue, 11 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CWE-862

Tue, 11 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.
Title Ray Enterprise Translation <= 1.7.3 - Subscriber+ Language Addition and Deletion
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published: 2026-08-11T06:00:12.300Z

Updated: 2026-08-12T19:07:12.291Z

Reserved: 2026-07-03T08:37:24.607Z

Link: CVE-2026-14549

cve-icon Vulnrichment

Updated: 2026-08-12T19:07:08.238Z

cve-icon NVD

Status : Received

Published: 2026-08-11T06:17:13.120

Modified: 2026-08-12T20:17:35.580

Link: CVE-2026-14549

cve-icon Redhat

No data.