AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14548

MEDIUM · CVSS 6.5 EPSS 0.17%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Ray Enterprise Translation plugin for WordPress versions up to 1.7.3 is vulnerable due to the lack of capability and nonce checks on an AJAX action, enabling any authenticated user, including those with Subscriber roles, to overwrite the administrator-configured translation API token with arbitrary values. This could lead to unauthorized access to translation services and potential data manipulation. WordPress site administrators using this plugin should prioritize applying patches or updates to mitigate the risk of exploitation.

CVE
CVE-2026-14548
Severity
MEDIUM
CVSS
6.5
EPSS
0.17%
WordPress

Original NVD Description

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.