
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0745 is a Server-Side Request Forgery (SSRF) vulnerability in the User Language Switch plugin for WordPress, affecting all versions up to and including 1.6.10. The flaw stems from missing URL validation in the download_language() function, enabling authenticated attackers with Administrator-level access to make arbitrary web requests from the server. It was published on February 14, 2026, with a CVSS v3.1 base score of 5.5 (Medium) (Red Hat CVE, Feedly).
The root cause is classified as CWE-918 (Server-Side Request Forgery), arising from the absence of URL validation in the plugin's download_language() function. An authenticated attacker with Administrator-level privileges can supply a crafted URL to this function, causing the WordPress server to issue HTTP requests to arbitrary internal or external destinations. Because the scope is changed (S:C in CVSS), the requests originate from the web application's network context, potentially reaching internal services not directly accessible from the internet. A proof-of-concept exploit has been published on GitHub (PoC GitHub, Red Hat CVE).
Successful exploitation allows an authenticated administrator to query and potentially modify information from internal services that are otherwise inaccessible from outside the network. This can result in exposure of sensitive internal data (low confidentiality impact) and unauthorized modification of internal service configurations (low integrity impact). Availability is not directly impacted, but the ability to pivot to internal infrastructure increases the risk of lateral movement within the hosting environment (Red Hat CVE, Feedly).
A proof-of-concept exploit is publicly available on GitHub (added February 15, 2026), but there is no evidence of active in-the-wild exploitation at this time (PoC GitHub). The EPSS score is approximately 0.03%, reflecting a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires Administrator-level authentication, which significantly limits the attacker pool (Feedly).
download_language() function, supplying an attacker-controlled or internal URL as the download target parameter.http://169.254.169.254/latest/meta-data/ for cloud metadata, or internal service endpoints like http://192.168.1.1/admin).169.254.169.254).download_language() function endpoint with unexpected or internal URLs as parameters; repeated requests to this endpoint from a single admin account.Update the User Language Switch plugin to a version beyond 1.6.10 as soon as a patched release becomes available. In the interim, restrict Administrator-level access to only trusted and necessary users, and consider disabling the plugin if it is not actively required. Implement network segmentation and outbound firewall rules on the web server to restrict connections to only necessary external and internal services, limiting the blast radius of any SSRF exploitation. Monitor outbound traffic from the WordPress server for anomalous requests to internal resources (Red Hat CVE, Feedly).
Wordfence included CVE-2026-0745 in their weekly WordPress vulnerability report for February 9–15, 2026, highlighting it as part of a broader set of plugin vulnerabilities (Wordfence Blog). RedPacket Security flagged the vulnerability via their CVE alert service and Mastodon social feed shortly after disclosure. The security community's reaction has been measured given the requirement for Administrator-level authentication, which limits practical risk for most deployments.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."