CVE-2026-0745: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-0745 is a Server-Side Request Forgery (SSRF) vulnerability in the User Language Switch plugin for WordPress, affecting all versions up to and including 1.6.10. The flaw stems from missing URL validation in the download_language() function, enabling authenticated attackers with Administrator-level access to make arbitrary web requests from the server. It was published on February 14, 2026, with a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), arising from the absence of URL validation in the plugin's download_language() function. An authenticated attacker with Administrator-level privileges can supply a crafted URL to this function, causing the WordPress server to issue HTTP requests to arbitrary internal or external destinations. Because the scope is changed (S:C in CVSS), the requests originate from the web application's network context, potentially reaching internal services not directly accessible from the internet. A proof-of-concept exploit has been published on GitHub (PoC GitHub, Red Hat CVE).

Impact

Successful exploitation allows an authenticated administrator to query and potentially modify information from internal services that are otherwise inaccessible from outside the network. This can result in exposure of sensitive internal data (low confidentiality impact) and unauthorized modification of internal service configurations (low integrity impact). Availability is not directly impacted, but the ability to pivot to internal infrastructure increases the risk of lateral movement within the hosting environment (Red Hat CVE, Feedly).

Exploitability

A proof-of-concept exploit is publicly available on GitHub (added February 15, 2026), but there is no evidence of active in-the-wild exploitation at this time (PoC GitHub). The EPSS score is approximately 0.03%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires Administrator-level authentication, which significantly limits the attacker pool (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the User Language Switch plugin version 1.6.10 or earlier using tools like WPScan or Shodan, or by inspecting plugin metadata in publicly accessible WordPress installations.
  2. Obtain Administrator credentials: Acquire valid WordPress Administrator credentials through phishing, credential stuffing, or other means, as the vulnerability requires high-privilege authentication.
  3. Craft malicious request: Log in to the WordPress admin panel and send a crafted HTTP request targeting the download_language() function, supplying an attacker-controlled or internal URL as the download target parameter.
  4. Trigger SSRF: The server processes the unvalidated URL and issues an HTTP request to the specified destination (e.g., http://169.254.169.254/latest/meta-data/ for cloud metadata, or internal service endpoints like http://192.168.1.1/admin).
  5. Harvest response data: Capture the server's response, which may contain sensitive internal data such as cloud instance metadata, internal API responses, or configuration details, enabling further lateral movement or privilege escalation (PoC GitHub, Red Hat CVE).

Indicators of compromise

  • Network: Unusual outbound HTTP/HTTPS requests from the WordPress server to internal IP ranges (e.g., RFC 1918 addresses: 10.x.x.x, 172.16.x.x, 192.168.x.x) or cloud metadata endpoints (e.g., 169.254.169.254).
  • Logs: WordPress or web server access logs showing POST or GET requests to the download_language() function endpoint with unexpected or internal URLs as parameters; repeated requests to this endpoint from a single admin account.
  • Network: Outbound connections from the web server to non-standard ports or services that are not part of normal plugin update traffic.
  • File System: Unexpected files downloaded to the WordPress plugin or uploads directory as a result of SSRF-triggered downloads from internal or external sources.

Mitigation and workarounds

Update the User Language Switch plugin to a version beyond 1.6.10 as soon as a patched release becomes available. In the interim, restrict Administrator-level access to only trusted and necessary users, and consider disabling the plugin if it is not actively required. Implement network segmentation and outbound firewall rules on the web server to restrict connections to only necessary external and internal services, limiting the blast radius of any SSRF exploitation. Monitor outbound traffic from the WordPress server for anomalous requests to internal resources (Red Hat CVE, Feedly).

Community reactions

Wordfence included CVE-2026-0745 in their weekly WordPress vulnerability report for February 9–15, 2026, highlighting it as part of a broader set of plugin vulnerabilities (Wordfence Blog). RedPacket Security flagged the vulnerability via their CVE alert service and Mastodon social feed shortly after disclosure. The security community's reaction has been measured given the requirement for Administrator-level authentication, which limits practical risk for most deployments.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management