Impact
The Ray Enterprise Translation plugin for WordPress version 1.7.3 and older contains an AJAX action that performs no capability or nonce checks. Because no authentication guard is enforced, any authenticated user—including users with the Subscriber role—can invoke this action and overwrite the API token that the administrator has configured for the translation service. This allows an attacker to replace the legitimate token with a malicious one, potentially enabling unauthorized use of the translation API or bypassing intended restrictions.
Affected Systems
WordPress sites running the Ray Enterprise Translation plugin version 1.7.3 or earlier.
Risk and Exploitability
No CVSS score is provided, and EPSS data is unavailable, but the vulnerability is listed as not in the CISA KEV catalog. The likely attack path is via the vulnerable AJAX endpoint accessible to any authenticated user; the attacker must first be logged into the site with at least Subscriber privileges. Once the token is replaced, the attacker can use or abuse the translation service, leading to potential data exfiltration, service disruption, or downstream abuse of the API. The risk is considered moderate to high due to the impact on authentication credentials and the lack of exploit mitigation controls.
OpenCVE Enrichment