CyberRota Analysis
AI-GeneratedThe Ray Enterprise Translation plugin for WordPress versions up to 1.7.3 is vulnerable due to the lack of capability and nonce checks on an AJAX action, enabling any authenticated user, including those with Subscriber roles, to overwrite the administrator-configured translation API token with arbitrary values. This could lead to unauthorized access to translation services and potential data manipulation. WordPress site administrators using this plugin should prioritize applying patches or updates to mitigate the risk of exploitation.
Original NVD Description
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.