CyberRota Analysis
AI-GeneratedThe Ray Enterprise Translation plugin for WordPress versions up to 1.7.3 is vulnerable due to a lack of capability and nonce checks on specific AJAX actions, enabling any authenticated user, including those with minimal permissions like Subscribers, to modify or remove the site's language settings. This could lead to unauthorized changes in site localization, potentially impacting user experience and site functionality. WordPress site administrators, especially those using this plugin, should prioritize addressing this vulnerability to prevent misuse by authenticated users.
Original NVD Description
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to add or delete the site's configured languages.