Description
The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.
Published: 2026-08-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ray Enterprise Translation plugin for WordPress version 1.7.3 and older contains an AJAX action that performs no capability or nonce checks. Because no authentication guard is enforced, any authenticated user—including users with the Subscriber role—can invoke this action and overwrite the API token that the administrator has configured for the translation service. This allows an attacker to replace the legitimate token with a malicious one, potentially enabling unauthorized use of the translation API or bypassing intended restrictions.

Affected Systems

WordPress sites running the Ray Enterprise Translation plugin version 1.7.3 or earlier.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. With an EPSS score of less than 1% and not listed in the CISA KEV catalog, the likelihood of exploitation is low, but the impact remains significant. The attack path is via the vulnerable AJAX endpoint that is accessible to any authenticated user, so an attacker only needs Subscriber-level access to overwrite the administrator-configured API token. Once the token is replaced, the attacker could potentially use the translation API for unauthorized operations or bypass intended restrictions. The risk is considered moderate due to the impact on authentication credentials and the lack of exploit mitigation controls.

Generated by OpenCVE AI on August 13, 2026 at 04:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Ray Enterprise Translation plugin to a version newer than 1.7.3
  • If an upgrade is not immediately possible, deny the Subscriber role permission to access the vulnerable AJAX action or disable it using a security plugin
  • Regenerate and revoke any translation API tokens that may have been overwritten or exposed

Generated by OpenCVE AI on August 13, 2026 at 04:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Lingotek-translation
Lingotek-translation ray Enterprise Translation
Wordpress
Wordpress wordpress
Vendors & Products Lingotek-translation
Lingotek-translation ray Enterprise Translation
Wordpress
Wordpress wordpress

Tue, 11 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Tue, 11 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing any authenticated user, including Subscribers, to overwrite the administrator-configured translation API token with an arbitrary value.
Title Ray Enterprise Translation <= 1.7.3 - Subscriber+ Arbitrary API Token Update
References

Subscriptions

Lingotek-translation Ray Enterprise Translation
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-12T19:03:24.410Z

Reserved: 2026-07-03T08:36:39.352Z

Link: CVE-2026-14548

cve-icon Vulnrichment

Updated: 2026-08-12T19:03:16.284Z

cve-icon NVD

Status : Deferred

Published: 2026-08-11T06:17:13.017

Modified: 2026-08-26T16:30:52.723

Link: CVE-2026-14548

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T04:45:02Z

Weaknesses