CVE-2026-14549
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-14549 is a Missing Authorization (CWE-862) vulnerability in the Ray Enterprise Translation WordPress plugin (also known as lingotek-translation) affecting all versions through 1.7.3. The flaw allows any authenticated user — including those with the low-privilege Subscriber role — to add or delete the site's configured languages via an unprotected AJAX action. It was publicly disclosed on August 8, 2026, with the CVE published on August 11, 2026. The CVSS score is 4.3 (Medium) (WPScan, Github Advisory).

Détails techniques

The root cause is a complete absence of capability checks and nonce verification on at least one WordPress AJAX action registered by the plugin, classified as CWE-862 (Missing Authorization) and mapped to OWASP Top 10 A5: Broken Access Control (WPScan). Because WordPress AJAX endpoints are accessible to any logged-in user by default, the unguarded action can be triggered by sending a crafted HTTP POST request to wp-admin/admin-ajax.php with the appropriate action parameter — no elevated privileges are required beyond a valid authenticated session. The vulnerability was discovered and reported by researcher Akshat Parikh (WPScan). A proof-of-concept is scheduled for public release on August 22, 2026, to allow time for users to update.

Impact

Successful exploitation allows any authenticated user with at minimum a Subscriber account to arbitrarily add or remove languages configured on the affected WordPress site, disrupting multilingual content delivery and potentially degrading site functionality for legitimate users (WPScan, Github Advisory). While the direct impact is limited to language configuration tampering (an integrity and availability concern), it could be leveraged to disrupt translation workflows or as part of a broader attack chain on sites with open user registration. There is no evidence of confidentiality impact or lateral movement potential from this vulnerability alone.

Exploitabilité

There is currently no public proof-of-concept exploit available, and no evidence of in-the-wild exploitation has been reported (Github Advisory). The EPSS score is 0.0, reflecting a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. A PoC is planned for public disclosure on August 22, 2026 (WPScan).

Étapes d’exploitation

  1. Reconnaissance: Identify WordPress sites running the Ray Enterprise Translation (lingotek-translation) plugin version ≤ 1.7.3 using tools such as WPScan or by inspecting publicly accessible plugin metadata (e.g., readme.txt).
  2. Obtain authenticated access: Register or log in as any low-privilege user (e.g., Subscriber) on the target WordPress site — open registration is common on many WordPress installations.
  3. Identify the vulnerable AJAX action: Review the plugin's source code or intercept legitimate AJAX requests to identify the unprotected action parameter name used for language management.
  4. Craft malicious AJAX request: Send an HTTP POST request to wp-admin/admin-ajax.php with the identified action parameter and appropriate data payload (e.g., language code to add or delete), including a valid WordPress authentication cookie but no nonce.
  5. Achieve unauthorized modification: The server processes the request without capability or nonce validation, adding or deleting the targeted language configuration on the site (WPScan).

Indicateurs de compromis

  • Network: Unusual POST requests to wp-admin/admin-ajax.php from low-privilege user sessions, particularly with action parameters related to language management (e.g., adding or deleting language codes).
  • Logs: WordPress access logs showing repeated AJAX requests to admin-ajax.php from Subscriber-level accounts outside of normal administrative hours; absence of nonce tokens in request parameters for language-related actions.
  • Application: Unexpected changes to the site's configured language list (additions or deletions) not initiated by administrators; review the plugin's language settings in the WordPress admin panel for unauthorized modifications.

Atténuation et solutions de contournement

The primary remediation is to update the Ray Enterprise Translation plugin to a version newer than 1.7.3 once a patched release becomes available (Github Advisory). Note that WPScan currently lists "No known fix" for the lingotek-translation plugin, so administrators should monitor the plugin's repository and the WPScan vulnerability database for patch availability (WPScan). As interim workarounds: disable open user registration to reduce the pool of potential attackers, restrict the Subscriber role's access where possible, consider deactivating the plugin until a patch is released, and monitor AJAX requests for unauthorized language modification attempts.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-16974MEDIUM6.4
  • kirki
NonOuiAug 11, 2026
CVE-2026-14549NONEN/A
  • lingotek-translation
NonNonAug 11, 2026
CVE-2026-14548NONEN/A
  • lingotek-translation
NonNonAug 11, 2026
CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NonOuiAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NonOuiAug 10, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités