AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-14549

MEDIUM · CVSS 4.3 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The Ray Enterprise Translation plugin for WordPress versions up to 1.7.3 is vulnerable due to a lack of capability and nonce checks on specific AJAX actions, enabling any authenticated user, including those with minimal permissions like Subscribers, to modify or remove the site's language settings. This could lead to unauthorized changes in site localization, potentially impacting user experience and site functionality. WordPress site administrators, especially those using this plugin, should prioritize addressing this vulnerability to prevent misuse by authenticated users.

CVE
CVE-2026-14549
Severity
MEDIUM
CVSS
4.3
EPSS
0.15%
WordPress

Original NVD Description

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.