
PEACH
Un cadre d’isolation des locataires
CVE-2026-14549 is a Missing Authorization (CWE-862) vulnerability in the Ray Enterprise Translation WordPress plugin (also known as lingotek-translation) affecting all versions through 1.7.3. The flaw allows any authenticated user — including those with the low-privilege Subscriber role — to add or delete the site's configured languages via an unprotected AJAX action. It was publicly disclosed on August 8, 2026, with the CVE published on August 11, 2026. The CVSS score is 4.3 (Medium) (WPScan, Github Advisory).
The root cause is a complete absence of capability checks and nonce verification on at least one WordPress AJAX action registered by the plugin, classified as CWE-862 (Missing Authorization) and mapped to OWASP Top 10 A5: Broken Access Control (WPScan). Because WordPress AJAX endpoints are accessible to any logged-in user by default, the unguarded action can be triggered by sending a crafted HTTP POST request to wp-admin/admin-ajax.php with the appropriate action parameter — no elevated privileges are required beyond a valid authenticated session. The vulnerability was discovered and reported by researcher Akshat Parikh (WPScan). A proof-of-concept is scheduled for public release on August 22, 2026, to allow time for users to update.
Successful exploitation allows any authenticated user with at minimum a Subscriber account to arbitrarily add or remove languages configured on the affected WordPress site, disrupting multilingual content delivery and potentially degrading site functionality for legitimate users (WPScan, Github Advisory). While the direct impact is limited to language configuration tampering (an integrity and availability concern), it could be leveraged to disrupt translation workflows or as part of a broader attack chain on sites with open user registration. There is no evidence of confidentiality impact or lateral movement potential from this vulnerability alone.
There is currently no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported (Github Advisory). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A PoC is planned for public disclosure on August 22, 2026 (WPScan).
readme.txt).action parameter name used for language management.wp-admin/admin-ajax.php with the identified action parameter and appropriate data payload (e.g., language code to add or delete), including a valid WordPress authentication cookie but no nonce.wp-admin/admin-ajax.php from low-privilege user sessions, particularly with action parameters related to language management (e.g., adding or deleting language codes).admin-ajax.php from Subscriber-level accounts outside of normal administrative hours; absence of nonce tokens in request parameters for language-related actions.The primary remediation is to update the Ray Enterprise Translation plugin to a version newer than 1.7.3 once a patched release becomes available (Github Advisory). Note that WPScan currently lists "No known fix" for the lingotek-translation plugin, so administrators should monitor the plugin's repository and the WPScan vulnerability database for patch availability (WPScan). As interim workarounds: disable open user registration to reduce the pool of potential attackers, restrict the Subscriber role's access where possible, consider deactivating the plugin until a patch is released, and monitor AJAX requests for unauthorized language modification attempts.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."