Impact
The Ray Enterprise Translation plugin for WordPress version 1.7.3 and older contains an AJAX action that performs no capability or nonce checks. Because no authentication guard is enforced, any authenticated user—including users with the Subscriber role—can invoke this action and overwrite the API token that the administrator has configured for the translation service. This allows an attacker to replace the legitimate token with a malicious one, potentially enabling unauthorized use of the translation API or bypassing intended restrictions.
Affected Systems
WordPress sites running the Ray Enterprise Translation plugin version 1.7.3 or earlier.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. With an EPSS score of less than 1% and not listed in the CISA KEV catalog, the likelihood of exploitation is low, but the impact remains significant. The attack path is via the vulnerable AJAX endpoint that is accessible to any authenticated user, so an attacker only needs Subscriber-level access to overwrite the administrator-configured API token. Once the token is replaced, the attacker could potentially use the translation API for unauthorized operations or bypass intended restrictions. The risk is considered moderate due to the impact on authentication credentials and the lack of exploit mitigation controls.
OpenCVE Enrichment